Show filters
30 Total Results
Displaying 11-20 of 30
Sort by:
Attacker Value
Unknown
CVE-2009-4577
Disclosure Date: January 06, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the MDForum module 2.x through 2.07 for MAXdev MDPro allows remote attackers to execute arbitrary SQL commands via the c parameter to index.php.
0
Attacker Value
Unknown
CVE-2008-7038
Disclosure Date: August 24, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in a showgall action to modules.php. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.
0
Attacker Value
Unknown
CVE-2009-2618
Disclosure Date: July 27, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results action to modules.php.
0
Attacker Value
Unknown
CVE-2009-2307
Disclosure Date: July 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbitrary SQL commands via the rid parameter in a viewrecords action to modules.php.
0
Attacker Value
Unknown
CVE-2009-0728
Disclosure Date: February 24, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showpic action to index.php.
0
Attacker Value
Unknown
CVE-2007-5222
Disclosure Date: October 05, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Firefox ID=" substring in a Referer HTTP header.
0
Attacker Value
Unknown
CVE-2007-3938
Disclosure Date: July 21, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a view action in the Topics module, a different vulnerability than CVE-2006-1676.
0
Attacker Value
Unknown
CVE-2006-7112
Disclosure Date: March 06, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading a GIF image using AddDownload or injecting PHP code into a log file, then accessing it.
0
Attacker Value
Unknown
CVE-2007-0624
Disclosure Date: January 31, 2007 (last updated October 04, 2023)
user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a ' (quote) character, and possibly other invalid values, in the uname parameter in a userinfo operation.
0
Attacker Value
Unknown
CVE-2007-0623
Disclosure Date: January 31, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter.
0