CRITICAL9.8
GHSA-3fj4-q72x-x2g9
ADOdb Library SQL Injection
Quick fix
GHSA-3fj4-q72x-x2g9 — adodb/adodb-php: upgrade to the fixed version with the command below.
composer require adodb/adodb-php:^5.20.7Details
The `qstr` method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/adodb/adodb-php
Introduced in:
5.0Fixed in: 5.20.7Fix
composer require adodb/adodb-php:^5.20.7References
- https://nvd.nist.gov/vuln/detail/CVE-2016-7405[ADVISORY]
- https://github.com/ADOdb/ADOdb/issues/226[WEB]
- https://github.com/ADOdb/ADOdb/commit/bd9eca9f40220f9918ec3cc7ae9ef422b3e448b8[WEB]
- https://github.com/ADOdb/ADOdb/blob/v5.20.7/docs/changelog.md[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LT3WU77BRUJREZUYQ3ZQBMUIVIVIND4Y[WEB]
- https://security.gentoo.org/glsa/201701-59[WEB]
- https://web.archive.org/web/20210123170727/http://www.securityfocus.com/bid/92969[WEB]
- http://www.openwall.com/lists/oss-security/2016/09/07/8[WEB]
- http://www.openwall.com/lists/oss-security/2016/09/15/1[WEB]