VYPR
Unrated severityNVD Advisory· Published Mar 6, 2007· Updated Apr 23, 2026

CVE-2006-7112

CVE-2006-7112

Description

Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading a GIF image using AddDownload or injecting PHP code into a log file, then accessing it.

Affected products

1
  • cpe:2.3:a:maxdev:mdpro:*:*:*:*:*:*:*:*
    Range: <=1.0.76

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.