CVE-2016-4855Cross-site Scripting in Adodb-php

CWE-79Cross-site Scripting10 documents6 sources
Severity
6.1MEDIUMNVD
EPSS
0.4%
top 41.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateJun 10

Description

Cross-site scripting vulnerability in ADOdb versions prior to 5.20.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

Packagistadodb/adodb-php< 5.20.6
debiandebian/libphp-adodb< libphp-adodb 5.20.6-1 (bookworm)
CVEListV5adodb/adodbversions prior to 5.20.6

🔴Vulnerability Details

4
OSV
libphp-adodb vulnerabilities2024-06-10
GHSA
ADOdb Cross-site scripting vulnerability in old test script2022-05-17
OSV
ADOdb Cross-site scripting vulnerability in old test script2022-05-17
OSV
CVE-2016-4855: Cross-site scripting vulnerability in ADOdb versions prior to 52017-05-12

📋Vendor Advisories

2
Ubuntu
ADOdb vulnerabilities2024-06-10
Debian
CVE-2016-4855: libphp-adodb - Cross-site scripting vulnerability in ADOdb versions prior to 5.20.6 allows remo...2016

💬Community

3
Bugzilla
CVE-2016-4855 php-adodb: adodb: cross-site scripting in test script [fedora-all]2016-09-06
Bugzilla
CVE-2016-4855 php-adodb: adodb: cross-site scripting in test script [epel-all]2016-09-06
Bugzilla
CVE-2016-4855 adodb: cross-site scripting in test script2016-09-06