Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Mdforum HIGH 7.5
CVE-2009-4577

SQL injection vulnerability in the MDForum module 2.x through 2.07 for MAXdev MDPro allows remote attackers to execute arbitrary SQL commands via the…

No fix yet
Fix from $1,950 2010-01-06
My Egallery HIGH 7.5
CVE-2008-7038

SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in…

No fix yet
Fix from $1,950 2009-08-24
Mdpro HIGH 7.5
CVE-2009-2618

SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to execute arbitrary SQL commands …

No fix yet
Fix from $1,950 2009-07-27
My Egallery HIGH 7.5
CVE-2009-0728

SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL command…

No fix yet
Fix from $1,950 2009-02-24
Mdpro HIGH 7.5
CVE-2007-0623

SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter.

No fix yet
Fix from $1,950 2007-01-31
Mdpro MEDIUM 5.0
CVE-2007-0624

user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a ' (quote) character, and possibly other invalid values, in the …

Mitigation only
Fix from $1,600 2007-01-31
Md Pro HIGH 7.5
CVE-2005-2885EPSS 9%

The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which…

No fix yet
Fix from $1,950 2005-09-14
Md Pro MEDIUM 5.0
CVE-2005-2887

MAXdev MD-Pro 1.0.73, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to (1) wiki.php, (2…

No fix yet
Fix from $1,600 2005-09-14