CVE-2006-1676

MAXdev MDPro <1.076 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-1676. PoCs published by king_purba.

AI-analyzed exploit summary The provided code is a writeup describing an SQL injection vulnerability in MAXDEV CMS. It includes example URLs demonstrating the vulnerability but does not contain executable exploit code.

Description

SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a display action, which is not properly handled in PNuserapi.PHP.

Exploits (1)

exploitdb WRITEUP VERIFIED
by king_purba · textwebappsphp
https://www.exploit-db.com/exploits/27576

The provided code is a writeup describing an SQL injection vulnerability in MAXDEV CMS. It includes example URLs demonstrating the vulnerability but does not contain executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: MAXDEV CMS
No auth needed
Prerequisites: Access to the vulnerable MAXDEV CMS instance
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17399
URL Repurposed x_refsource_confirm
http://www.maxdev.com/Article592.phtml
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25710
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/437831/100/100/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19578
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/430370/100/0/threaded
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1282

Scores

EPSS 0.0122
EPSS Percentile 65.6%

Details

CWE
CWE-89
Status published
Products (3)
maxdev/md-pro 1.0.72
maxdev/md-pro 1.0.73
maxdev/md-pro < 1.0.75
Published Apr 11, 2006
Tracked Since Feb 18, 2026