CVE-2007-3938: SQL Injection
Published Jul 21, 2007
·Updated
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a view action in the Topics module, a different vulnerability than CVE-2006-1676.
Affected Software
1 affected component
MAXdev MDPro<=1.0.8x
Event History
Jul 21, 2007
CVE Published
12:30 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3938?
CVE-2007-3938 is considered a high severity SQL injection vulnerability.
2
How do I fix CVE-2007-3938?
To fix CVE-2007-3938, update MAXdev MDPro to version 1.0.8 or later, released after 20070720.
3
What systems are affected by CVE-2007-3938?
CVE-2007-3938 affects MAXdev MDPro versions 1.0.8x and earlier.
4
What impact does CVE-2007-3938 have?
CVE-2007-3938 allows remote attackers to execute arbitrary SQL commands, potentially compromising the database.
5
Is CVE-2007-3938 a new vulnerability?
CVE-2007-3938 was discovered in 2007 and is not a new vulnerability.