CVE-2016-4855: XSS
Published Aug 28, 2016
·Updated
Cross-site scripting vulnerability in ADOdb versions prior to 5.20.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
7 affected componentsFixes available
composer/adodb/adodb-php<5.20.6
composer/adodb/adodb-php<5.20.6
5.20.6
ubuntu/libphp-adodb<5.15-1+
5.15-1+
ubuntu/libphp-adodb<5.20.6
5.20.6
ubuntu/libphp-adodb<5.20.3-1ubuntu1+
5.20.3-1ubuntu1+
debian/libphp-adodb
5.20.14-1+deb10u15.20.19-1+deb11u15.21.4-1
Adodb Project Adodb<=5.20.5
Remediation
Patch Available
Event History
Aug 28, 2016
Advisory Published
11:50 PM
May 12, 2017
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Jun 11, 2024
Data Sourced
via Launchpad·04:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4855?
CVE-2016-4855 is classified as a Cross-site scripting (XSS) vulnerability, which can lead to significant security risks for affected applications.
2
How do I fix CVE-2016-4855?
To mitigate CVE-2016-4855, upgrade ADOdb to version 5.20.6 or later.
3
What software is affected by CVE-2016-4855?
CVE-2016-4855 affects ADOdb versions prior to 5.20.6.
4
Can CVE-2016-4855 be exploited remotely?
Yes, CVE-2016-4855 can be exploited remotely, allowing attackers to inject arbitrary web scripts or HTML.
5
What are the potential impacts of CVE-2016-4855?
Successful exploitation of CVE-2016-4855 may lead to data theft, session hijacking, or other malicious activities against users.