← Back

Mxmania

mxmania

6 CVEs • 5 products

Products (5)

Click to collapse
Toggle

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mxmania
1Gallery Mx
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in pics_pre.asp in Gallery MX 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
1Mxmania
1Calendar Mx Professional
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
1Mxmania
1Calendar Mx Basic
Apr 23, 2026
Dec 29, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Calendar MX BASIC 1.0.2 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for calendar.mdb. NOTE: The...Show more
Calendar MX BASIC 1.0.2 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for calendar.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Mxmania
1Mxmania File Upload Manager
Apr 23, 2026
Dec 29, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in detail.asp in Mxmania File Upload Manager (FUM) 1.0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
1Mxmania
1Calendar Mx Basic
Apr 23, 2026
Dec 28, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: The provenance of this information is unkno...Show more
SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Mxmania
1Newsletter Mx
Apr 23, 2026
Dec 28, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/admin_mail_adressee.asp in Newsletter MX 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.