← Vulnerability feed

Vulnerability record · CVE-2006-4964 · published 23 September 2006

CVE-2006-4964: Maxdev md-pro vulnerability

Maxdev · Md Pro

Cross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before 20060918 allows remote attackers to inject arbitrary web script or HTML via (1) vectors that bypass the XSS protection mechanisms of the pnVarCleanFromInput function, and (2) unspecified vectors related to the AntiCracker.

6.8 CVSS 2.0 Medium EPSS 1.4% · top 28.4%
6.8CVSS 2.0 base score
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before 20060918 allows remote attackers to inject arbitrary web script or HTML via (1) vectors that bypass the XSS protection mechanisms of the pnVarCleanFromInput function, and (2) unspecified vectors related to the AntiCracker.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-4964 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-2840Maxdev md-pro vulnerabilityMultiple unknown vulnerabilities in MAXdev MD-Pro 1.0.72 and earlier have unknown impact and unspecified attack vectors, in one or more of the (1) Do…EPSS 1.4%7.5CVE-2005-2885Maxdev md-pro vulnerabilityThe Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which…EPSS 8.7%6.4CVE-2006-1676Maxdev md-pro sql injection vulnerabilitySQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions bef…EPSS 1.2%6.4CVE-2006-1677Maxdev md-pro information exposure vulnerabilityMAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via a direct …EPSS 1.5%5.0CVE-2006-5565Maxdev md-pro vulnerabilityCRLF injection vulnerability in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary HTTP headers via a CRLF sequence in the (1) name, (2…EPSS 1.4%5.0CVE-2005-2887Maxdev md-pro vulnerabilityMAXdev MD-Pro 1.0.73, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to (1) wiki.php, (2…EPSS 1.5%4.3CVE-2006-5564Maxdev md-pro vulnerabilityCross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the o…EPSS 1.7%4.3CVE-2005-2839Maxdev md-pro vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.72 allow remote attackers to inject arbitrary web script or HTML via (1) dl-…EPSS 0.95%

Source: NIST National Vulnerability Database (record CVE-2006-4964), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.