First published: Mon Jun 10 2024(Updated: )
It was discovered that the PDO driver in ADOdb was incorrectly handling string quotes. A remote attacker could possibly use this issue to perform SQL injection attacks. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-7405) It was discovered that ADOdb was incorrectly handling GET parameters in test.php. A remote attacker could possibly use this issue to execute cross-site scripting (XSS) attacks. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4855) Emmet Leahy discovered that ADOdb was incorrectly handling string quotes in PostgreSQL connections. A remote attacker could possibly use this issue to bypass authentication. (CVE-2021-3850)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libphp-adodb | <5.20.19-1ubuntu0.1 | 5.20.19-1ubuntu0.1 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/libphp-adodb | <5.20.16-1ubuntu0.1~esm1 | 5.20.16-1ubuntu0.1~esm1 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/libphp-adodb | <5.20.9-1ubuntu0.1~esm1 | 5.20.9-1ubuntu0.1~esm1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/libphp-adodb | <5.20.3-1ubuntu1+esm1 | 5.20.3-1ubuntu1+esm1 |
Ubuntu Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)