Skip to content
Noroxi

maxdev records

21 published records for vendor maxdev.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
11
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

21 records
  • Multiple unknown vulnerabilities in MAXdev MD-Pro 1.0.72 and earlier have unknown impact and unspecified attack vectors, in one or more of t

    CriticalCVSS 10.0No exploitEPSS 1%

    maxdev · md-proSep 7, 2005

  • CVE-2006-6869
    38Monitor

    Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabl

    CriticalCVSS 9.3Proof of conceptEPSS 3%

    maxdev · mdforumDec 31, 2006

  • CVE-2005-2885
    33Monitor

    The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensio

    HighCVSS 7.5Proof of conceptEPSS 9%

    maxdev · md-proSep 14, 2005

  • CVE-2007-0623
    31Monitor

    SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow p

    HighCVSS 7.5Proof of conceptEPSS 2%

    maxdev · mdproJan 31, 2007

  • CVE-2007-5222
    30Monitor

    SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Fi

    HighCVSS 7.5Proof of conceptEPSS 2%

    maxdev · mdproOct 4, 2007

  • CVE-2007-3938
    30Monitor

    SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attackers to execute arbi

    HighCVSS 7.5Proof of conceptEPSS 1%

    maxdev · mdproJul 20, 2007

  • CVE-2009-4577
    30Monitor

    SQL injection vulnerability in the MDForum module 2.x through 2.07 for MAXdev MDPro allows remote attackers to execute arbitrary SQL command

    HighCVSS 7.5No exploitEPSS 1%

    maxdev · mdproJan 6, 2010

  • CVE-2008-7038
    30Monitor

    SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid par

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpnuke · php-nukeAug 24, 2009

  • CVE-2009-2618
    30Monitor

    SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to execute arbitrary SQL

    HighCVSS 7.5Proof of conceptEPSS 1%

    maxdev · mdproJul 27, 2009

  • CVE-2009-0728
    30Monitor

    SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQ

    HighCVSS 7.5Proof of conceptEPSS 1%

    maxdev · my egalleryFeb 24, 2009

  • CVE-2009-2307
    30Monitor

    SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbit

    HighCVSS 7.5Proof of conceptEPSS 1%

    maxdev · cwguestbookJul 2, 2009

  • CVE-2006-4964
    27Monitor

    Cross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before 20060918 allows remote attackers to inject arbitrary web script or HT

    MediumCVSS 6.8No exploitEPSS 1%

    maxdev · md-proSep 23, 2006

  • CVE-2006-1677
    25Monitor

    MAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via

    MediumCVSS 6.4No exploitEPSS 1%

    maxdev · md-proApr 10, 2006

  • CVE-2006-1676
    25Monitor

    SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other ver

    MediumCVSS 6.4Proof of conceptEPSS 1%

    maxdev · md-proApr 10, 2006

  • CVE-2006-7112
    24Monitor

    Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary

    MediumCVSS 6.0Proof of conceptEPSS 2%

    maxdev · mdproMar 5, 2007

  • CVE-2005-2887
    20Monitor

    MAXdev MD-Pro 1.0.73, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to (1) wik

    MediumCVSS 5.0No exploitEPSS 2%

    maxdev · md-proSep 14, 2005

  • CVE-2006-5565
    20Monitor

    CRLF injection vulnerability in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary HTTP headers via a CRLF sequence in the (1)

    MediumCVSS 5.0No exploitEPSS 1%

    maxdev · md-proOct 27, 2006

  • CVE-2007-0624
    20Monitor

    user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a ' (quote) character, and possibly other invalid values

    MediumCVSS 5.0No exploitEPSS 1%

    maxdev · mdproJan 31, 2007

  • CVE-2006-5564
    17Monitor

    Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML

    MediumCVSS 4.3Proof of conceptEPSS 2%

    maxdev · md-proOct 27, 2006

  • CVE-2005-2886
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.73, and possibly earlier versions, allow remote attackers to inject

    MediumCVSS 4.3No exploitEPSS 1%

    maxdev · md-proSep 14, 2005

  • CVE-2005-2839
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.72 allow remote attackers to inject arbitrary web script or HTML vi

    MediumCVSS 4.3No exploitEPSS 1%

    maxdev · md-proSep 7, 2005