Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mdforum HIGH 7.5
CVE-2009-4577

SQL injection vulnerability in the MDForum module 2.x through 2.07 for MAXdev MDPro allows remote attackers to execute arbitrary SQL commands via the…

No fix yet
Fix from $1,950 2010-01-06
My Egallery HIGH 7.5
CVE-2008-7038

SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in…

No fix yet
Fix from $1,950 2009-08-24
Mdpro HIGH 7.5
CVE-2009-2618

SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to execute arbitrary SQL commands …

No fix yet
Fix from $1,950 2009-07-27
Cwguestbook HIGH 7.5
CVE-2009-2307

SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbitrary SQL …

Fix: after 2.1
Fix from $1,950 2009-07-02
My Egallery HIGH 7.5
CVE-2009-0728

SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL command…

No fix yet
Fix from $1,950 2009-02-24
Mdpro HIGH 7.5
CVE-2007-5222

SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Firefox ID=…

Patch available
Fix from $1,950 2007-10-05
Mdpro HIGH 7.5
CVE-2007-3938

SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attackers to execute arbitrary SQL…

Fix: after 1.0.8x
Fix from $1,950 2007-07-21
Mdpro MEDIUM 6.0
CVE-2006-7112

Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via…

Fix: after 1.0.76
Fix from $1,600 2007-03-06
Mdpro HIGH 7.5
CVE-2007-0623

SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter.

No fix yet
Fix from $1,950 2007-01-31
Mdpro MEDIUM 5.0
CVE-2007-0624

user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a ' (quote) character, and possibly other invalid values, in the …

Mitigation only
Fix from $1,600 2007-01-31
Mdforum HIGH 9.3
CVE-2006-6869

Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and re…

Fix: after 2.0.1
Fix from $1,950 2006-12-31
Md Pro MEDIUM 5.0
CVE-2006-5565

CRLF injection vulnerability in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary HTTP headers via a CRLF sequence in the (1) name, (2…

Fix: after 1.0.76
Fix from $1,600 2006-10-27
Md Pro MEDIUM 6.8
CVE-2006-4964

Cross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before 20060918 allows remote attackers to inject arbitrary web script or HTML via (1…

Fix: after 1.0.76
Fix from $1,600 2006-09-23
Md Pro MEDIUM 6.4
CVE-2006-1676

SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions bef…

Fix: after 1.0.75
Fix from $1,600 2006-04-11
Md Pro MEDIUM 6.4
CVE-2006-1677

MAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via a direct …

Fix: after 1.0.75
Fix from $1,600 2006-04-11
Md Pro HIGH 7.5
CVE-2005-2885EPSS 9%

The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which…

No fix yet
Fix from $1,950 2005-09-14
Md Pro MEDIUM 5.0
CVE-2005-2887

MAXdev MD-Pro 1.0.73, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to (1) wiki.php, (2…

No fix yet
Fix from $1,600 2005-09-14
Md Pro HIGH 10.0
CVE-2005-2840

Multiple unknown vulnerabilities in MAXdev MD-Pro 1.0.72 and earlier have unknown impact and unspecified attack vectors, in one or more of the (1) Do…

Fix: after 1.0.72
Fix from $1,950 2005-09-07