Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-1676. PoCs published by king_purba.
AI-analyzed exploit summary The provided code is a writeup describing an SQL injection vulnerability in MAXDEV CMS. It includes example URLs demonstrating the vulnerability but does not contain executable exploit code.
Description
SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a display action, which is not properly handled in PNuserapi.PHP.
Exploits (1)
The provided code is a writeup describing an SQL injection vulnerability in MAXDEV CMS. It includes example URLs demonstrating the vulnerability but does not contain executable exploit code.