USN-6825-1
Dashboard / Vulnerabilities / USN-6825-1
USN-6825-1
Summary: libphp-adodb vulnerabilities
Details: It was discovered that the PDO driver in ADOdb was incorrectly handling string quotes. A remote attacker could possibly use this issue to perform SQL injection attacks. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-7405) It was discovered that ADOdb was incorrectly handling GET parameters in test.php. A remote attacker could possibly use this issue to execute cross-site scripting (XSS) attacks. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4855) Emmet Leahy discovered that ADOdb was incorrectly handling string quotes in PostgreSQL connections. A remote attacker could possibly use this issue to bypass authentication. (CVE-2021-3850)
References: https://ubuntu.com/security/notices/USN-6825-1, https://ubuntu.com/security/CVE-2016-4855, https://ubuntu.com/security/CVE-2016-7405, https://ubuntu.com/security/CVE-2021-3850
Affected packages
Package
Name: libphp-adodb
Purl: pkg:deb/ubuntu/libphp-adodb?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
