← Vulnerability feed

Vulnerability record · CVE-2005-2885 · published 14 September 2005

CVE-2005-2885: Maxdev md-pro vulnerability

Maxdev · Md Pro

The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which could allow remote attackers to bypass file extension checks and execute arbitrary commands by uploading a file with a different extension, as demonstrated using .inc files.

7.5 CVSS 2.0 High EPSS 8.7% · top 5.0%
7.5CVSS 2.0 base score
8.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which could allow remote attackers to bypass file extension checks and execute arbitrary commands by uploading a file with a different extension, as demonstrated using .inc files.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2885 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-2840Maxdev md-pro vulnerabilityMultiple unknown vulnerabilities in MAXdev MD-Pro 1.0.72 and earlier have unknown impact and unspecified attack vectors, in one or more of the (1) Do…EPSS 1.4%6.8CVE-2006-4964Maxdev md-pro vulnerabilityCross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before 20060918 allows remote attackers to inject arbitrary web script or HTML via (1…EPSS 1.4%6.4CVE-2006-1676Maxdev md-pro sql injection vulnerabilitySQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions bef…EPSS 1.2%6.4CVE-2006-1677Maxdev md-pro information exposure vulnerabilityMAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via a direct …EPSS 1.5%5.0CVE-2006-5565Maxdev md-pro vulnerabilityCRLF injection vulnerability in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary HTTP headers via a CRLF sequence in the (1) name, (2…EPSS 1.4%5.0CVE-2005-2887Maxdev md-pro vulnerabilityMAXdev MD-Pro 1.0.73, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to (1) wiki.php, (2…EPSS 1.5%4.3CVE-2006-5564Maxdev md-pro vulnerabilityCross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the o…EPSS 1.7%4.3CVE-2005-2839Maxdev md-pro vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.72 allow remote attackers to inject arbitrary web script or HTML via (1) dl-…EPSS 0.95%

Source: NIST National Vulnerability Database (record CVE-2005-2885), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.