First published: Sun Aug 28 2016(Updated: )
Cross-site scripting vulnerability in ADOdb versions prior to 5.20.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
composer/adodb/adodb-php | <5.20.6 | |
composer/adodb/adodb-php | <5.20.6 | 5.20.6 |
ubuntu/libphp-adodb | <5.15-1+ | 5.15-1+ |
ubuntu/libphp-adodb | <5.20.6 | 5.20.6 |
ubuntu/libphp-adodb | <5.20.3-1ubuntu1+ | 5.20.3-1ubuntu1+ |
debian/libphp-adodb | 5.20.14-1+deb10u1 5.20.19-1+deb11u1 5.21.4-1 | |
ADOdb Lite | <=5.20.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4855 is classified as a Cross-site scripting (XSS) vulnerability, which can lead to significant security risks for affected applications.
To mitigate CVE-2016-4855, upgrade ADOdb to version 5.20.6 or later.
CVE-2016-4855 affects ADOdb versions prior to 5.20.6.
Yes, CVE-2016-4855 can be exploited remotely, allowing attackers to inject arbitrary web scripts or HTML.
Successful exploitation of CVE-2016-4855 may lead to data theft, session hijacking, or other malicious activities against users.