CVE-2006-1676 Information

Description

SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72 and possibly other versions before 1.076 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a display action which is not properly handled in PNuserapi.PHP.

Reference

http://secunia.com/advisories/19578 http://www.maxdev.com/Article592.phtml http://www.securityfocus.com/archive/1/430370/100/0/threaded http://www.securityfocus.com/archive/1/437831/100/100/threaded http://www.securityfocus.com/bid/17399 http://www.vupen.com/english/advisories/2006/1282 https://exchange.xforce.ibmcloud.com/vulnerabilities/25710

Share on: