Maxdev / Mdpro
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2009-2618 | SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to execute arbitrary SQL commands via the po… | HIGH | 7.5 | Jul 27, 2009 |
| CVE-2007-5222 | SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Firefox ID=" substrin… | HIGH | 7.5 | Oct 5, 2007 |
| CVE-2007-3938 | SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attackers to execute arbitrary SQL commands… | HIGH | 7.5 | Jul 21, 2007 |
| CVE-2006-7112 | Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVl… | MEDIUM | 6.0 | Mar 6, 2007 |
| CVE-2007-0624 | user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a ' (quote) character, and possibly other invalid values, in the uname para… | MEDIUM | 5.0 | Jan 31, 2007 |
| CVE-2007-0623 | SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter. | HIGH | 7.5 | Jan 31, 2007 |
Showing 1 to 6 of 6 CVEs