CVE-2007-3938
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a view action in the Topics module, a different vulnerability than CVE-2006-1676.
- Affected products
- Maxdev Md-Pro
- Maxdev Mdpro
- ≤ 1.0.8x
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 1.2% (66th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2007-07-21
CVE-2007-3938 at NVD
1 known exploit for CVE-2007-3938
Proof-of-concept code and exploit modules indexed by Sploitus