CVE-2016-7405
published 2016-10-03CVE-2016-7405: The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via…
PriorityP350critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.98%
85.8th percentile
The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adodb | adodb-php | >= 5.0 < 5.20.7 | 5.20.7 |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
| adodb_project | adodb | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libphp-adodb vulnerabilities
osv·2024-06-10·CVSS 6.1
CVE-2016-7405 [MEDIUM] libphp-adodb vulnerabilities
libphp-adodb vulnerabilities
It was discovered that the PDO driver in ADOdb was incorrectly handling
string quotes. A remote attacker could possibly use this issue to
perform SQL injection attacks. This issue only affected Ubuntu 16.04 LTS.
(CVE-2016-7405)
It was discovered that ADOdb was incorrectly handling GET parameters in
test.php. A remote attacker could possibly use this issue to execute
cross-site scripting (XSS) attacks. This issue only affected Ubuntu
16.04 LTS. (CVE-2016-4855)
Emmet Leahy discovered that ADOdb was incorrectly handling string quotes
in PostgreSQL connections. A remote attacker could possibly use this issue
to bypass authentication. (CVE-2021-3850)
OSV
ADOdb Library SQL Injection
osv·2022-05-17
CVE-2016-7405 [CRITICAL] ADOdb Library SQL Injection
ADOdb Library SQL Injection
The `qstr` method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.
GHSA
ADOdb Library SQL Injection
ghsa·2022-05-17
CVE-2016-7405 [CRITICAL] CWE-89 ADOdb Library SQL Injection
ADOdb Library SQL Injection
The `qstr` method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.
OSV
CVE-2016-7405: The qstr method in the PDO driver in the ADOdb Library for PHP before 5
osv·2016-10-03·CVSS 9.8
CVE-2016-7405 [CRITICAL] CVE-2016-7405: The qstr method in the PDO driver in the ADOdb Library for PHP before 5
The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.
Ubuntu
ADOdb vulnerabilities
vendor_ubuntu·2024-06-10·CVSS 6.1
CVE-2016-4855 [MEDIUM] ADOdb vulnerabilities
Title: ADOdb vulnerabilities
Summary: Several security issues were fixed in ADOdb.
It was discovered that the PDO driver in ADOdb was incorrectly handling
string quotes. A remote attacker could possibly use this issue to
perform SQL injection attacks. This issue only affected Ubuntu 16.04 LTS.
(CVE-2016-7405)
It was discovered that ADOdb was incorrectly handling GET parameters in
test.php. A remote attacker could possibly use this issue to execute
cross-site scripting (XSS) attacks. This issue only affected Ubuntu
16.04 LTS. (CVE-2016-4855)
Emmet Leahy discovered that ADOdb was incorrectly handling string quotes
in PostgreSQL connections. A remote attacker could possibly use this issue
to bypass authentication. (CVE-2021-3850)
Instructions: In general, a standard system update will ma
Debian
CVE-2016-7405: libphp-adodb - The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before...
vendor_debian·2016·CVSS 9.8
CVE-2016-7405 [CRITICAL] CVE-2016-7405: libphp-adodb - The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before...
The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.
Scope: local
bookworm: resolved (fixed in 5.20.6-1)
bullseye: resolved (fixed in 5.20.6-1)
forky: resolved (fixed in 5.20.6-1)
sid: resolved (fixed in 5.20.6-1)
trixie: resolved (fixed in 5.20.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7405 php-adodb: Incorrect quoting may allow SQL injection [fedora-all]
bugzilla·2016-09-15·CVSS 9.8
CVE-2016-7405 [CRITICAL] CVE-2016-7405 php-adodb: Incorrect quoting may allow SQL injection [fedora-all]
CVE-2016-7405 php-adodb: Incorrect quoting may allow SQL injection [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
Bugzilla
CVE-2016-7405 php-adodb: Incorrect quoting may allow SQL injection [epel-all]
bugzilla·2016-09-15·CVSS 9.8
CVE-2016-7405 [CRITICAL] CVE-2016-7405 php-adodb: Incorrect quoting may allow SQL injection [epel-all]
CVE-2016-7405 php-adodb: Incorrect quoting may allow SQL injection [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2016-7405 php-adodb: Incorrect quoting may allow SQL injection
bugzilla·2016-09-15·CVSS 9.8
CVE-2016-7405 [CRITICAL] CVE-2016-7405 php-adodb: Incorrect quoting may allow SQL injection
CVE-2016-7405 php-adodb: Incorrect quoting may allow SQL injection
In ADODB 5.20.4, using the PDO driver results in qstr not behaving properly, leading to SQL injection. The same method called with the MySQLi driver works as expected.
Upstream bug:
https://github.com/ADOdb/ADOdb/issues/226
Upstream fix:
https://github.com/ADOdb/ADOdb/commit/bd9eca9f40220f9918ec3cc7ae9ef422b3e448b8
References:
http://seclists.org/oss-sec/2016/q3/435
Discussion:
Created php-adodb tracking bugs for this issue:
Affects: fedora-all [bug 1376366]
Affects: epel-all [bug 1376367]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community
http://www.openwall.com/lists/oss-security/2016/09/07/8http://www.openwall.com/lists/oss-security/2016/09/15/1http://www.securityfocus.com/bid/92969https://github.com/ADOdb/ADOdb/blob/v5.20.7/docs/changelog.mdhttps://github.com/ADOdb/ADOdb/commit/bd9eca9f40220f9918ec3cc7ae9ef422b3e448b8https://github.com/ADOdb/ADOdb/issues/226https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LT3WU77BRUJREZUYQ3ZQBMUIVIVIND4Y/https://security.gentoo.org/glsa/201701-59http://www.openwall.com/lists/oss-security/2016/09/07/8http://www.openwall.com/lists/oss-security/2016/09/15/1http://www.securityfocus.com/bid/92969https://github.com/ADOdb/ADOdb/blob/v5.20.7/docs/changelog.mdhttps://github.com/ADOdb/ADOdb/commit/bd9eca9f40220f9918ec3cc7ae9ef422b3e448b8https://github.com/ADOdb/ADOdb/issues/226https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LT3WU77BRUJREZUYQ3ZQBMUIVIVIND4Y/https://security.gentoo.org/glsa/201701-59
2016-10-03
Published