CVE-2016-7405SQL Injection in Adodb-php

CWE-89SQL Injection10 documents6 sources
Severity
9.8CRITICALNVD
OSV6.1
EPSS
3.1%
top 13.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 3
Latest updateJun 10

Description

The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

Packagistadodb/adodb-php5.05.20.7
debiandebian/libphp-adodb< libphp-adodb 5.20.6-1 (bookworm)
NVDadodb_project/adodb27 versions+26

Also affects: Fedora 25

Patches

🔴Vulnerability Details

4
OSV
libphp-adodb vulnerabilities2024-06-10
OSV
ADOdb Library SQL Injection2022-05-17
GHSA
ADOdb Library SQL Injection2022-05-17
OSV
CVE-2016-7405: The qstr method in the PDO driver in the ADOdb Library for PHP before 52016-10-03

📋Vendor Advisories

2
Ubuntu
ADOdb vulnerabilities2024-06-10
Debian
CVE-2016-7405: libphp-adodb - The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before...2016

💬Community

3
Bugzilla
CVE-2016-7405 php-adodb: Incorrect quoting may allow SQL injection [fedora-all]2016-09-15
Bugzilla
CVE-2016-7405 php-adodb: Incorrect quoting may allow SQL injection [epel-all]2016-09-15
Bugzilla
CVE-2016-7405 php-adodb: Incorrect quoting may allow SQL injection2016-09-15