CVE-2006-1676: SQL Injection
SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a display action, which is not properly handled in PNuserapi.PHP.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1676?
CVE-2006-1676 is considered to have a medium severity due to the potential for remote SQL injection attacks.
How do I fix CVE-2006-1676?
To fix CVE-2006-1676, it is recommended to upgrade to version 1.0.76 or later of MAXdev MDPro.
Which versions of MAXdev MDPro are affected by CVE-2006-1676?
CVE-2006-1676 affects MAXdev MDPro versions 1.0.72, 1.0.73, and possibly earlier versions up to 1.0.75.
Can CVE-2006-1676 lead to data breaches?
Yes, CVE-2006-1676 can lead to data breaches as it allows attackers to execute arbitrary SQL commands.
What is SQL injection in relation to CVE-2006-1676?
SQL injection in CVE-2006-1676 refers to the exploitation of the topicid parameter, which allows attackers to manipulate database queries.