CVE-2007-5222: SQL Injection
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Firefox ID=" substring in a Referer HTTP header.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5222?
CVE-2007-5222 has a medium severity rating due to its potential to allow unauthorized SQL command execution.
How do I fix CVE-2007-5222?
To fix CVE-2007-5222, upgrade MAXdev MDPro to a version that addresses this vulnerability or implement proper input validation on the Referer HTTP header.
Which versions of MAXdev MDPro are affected by CVE-2007-5222?
CVE-2007-5222 affects MAXdev MDPro version 1.0.76.
What type of attack can be executed using CVE-2007-5222?
CVE-2007-5222 can be exploited for SQL injection attacks to execute arbitrary SQL commands against the application database.
Who can be affected by CVE-2007-5222?
Any users of MAXdev MDPro version 1.0.76 that have not mitigated this vulnerability may be susceptible to SQL injection attacks.