CVE-2016-7405: SQL Injection
The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.
Other sources
The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.
— Ubuntu
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7405?
CVE-2016-7405 has a medium severity rating due to its potential to allow SQL injection attacks.
How do I fix CVE-2016-7405?
To fix CVE-2016-7405, update the ADOdb Library to version 5.20.7 or later.
What versions are affected by CVE-2016-7405?
CVE-2016-7405 affects ADOdb versions prior to 5.20.7.
Can CVE-2016-7405 be exploited remotely?
Yes, CVE-2016-7405 can be exploited by remote attackers to perform SQL injection.
What is the impact of exploiting CVE-2016-7405?
Exploiting CVE-2016-7405 can lead to unauthorized access and manipulation of the database.