First published: Tue Feb 21 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
John Lim ADOdb | =4.71 | |
John Lim ADOdb | =4.66 | |
John Lim ADOdb | =4.70 | |
John Lim ADOdb | =4.68 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.