VendorsMaxdevmd-pro1.0.72
Vulnerabilities

Maxdev Md-pro 1.0.72

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2006-4964
Cross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before 20060918 allows remote attackers to inject arbitrary web script or HTML via (1) vectors that bypass the XSS protection mechanisms of the pnVarCleanFromInput function, and (2) unspecified vectors related to the AntiCracker.
Published 2006-09-23 · Modified
6.8EPSS 0.014
CVE-2006-1677
MAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via a direct request to includes/legacy.php.
Published 2006-04-10 · Modified
6.4EPSS 0.015
CVE-2006-1676
SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a display action, which is not properly handled in PNuserapi.PHP.
Published 2006-04-10 · Modified
6.41 PoCEPSS 0.012
CVE-2005-2839
Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.72 allow remote attackers to inject arbitrary web script or HTML via (1) dl-search.php or (2) wl-search.php.
Published 2005-09-07 · Modified
4.3EPSS 0.009