CVE-2007-0623: SQL Injection
Published Jan 31, 2007
·Updated
SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter.
Affected Software
1 affected component
MAXdev MDPro=1.0.76
Event History
Jan 31, 2007
CVE Published
06:28 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0623?
CVE-2007-0623 is considered to have a high severity due to the potential for arbitrary SQL command execution.
2
How do I fix CVE-2007-0623?
To fix CVE-2007-0623, validate and sanitize user input for the startrow parameter to prevent SQL injection.
3
What software is affected by CVE-2007-0623?
The vulnerable software is MAXdev MDPro version 1.0.76.
4
Who is responsible for addressing CVE-2007-0623?
It is the responsibility of the software maintainers or users to apply security patches or workarounds to mitigate CVE-2007-0623.
5
Can CVE-2007-0623 be exploited remotely?
Yes, CVE-2007-0623 can be exploited remotely, allowing attackers to execute arbitrary SQL commands.