First published: Wed Jan 31 2007(Updated: )
SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MD-Pro | =1.0.76 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0623 is considered to have a high severity due to the potential for arbitrary SQL command execution.
To fix CVE-2007-0623, validate and sanitize user input for the startrow parameter to prevent SQL injection.
The vulnerable software is MAXdev MDPro version 1.0.76.
It is the responsibility of the software maintainers or users to apply security patches or workarounds to mitigate CVE-2007-0623.
Yes, CVE-2007-0623 can be exploited remotely, allowing attackers to execute arbitrary SQL commands.