{"id":"MGASA-2016-0363","summary":"Updated php-adodb packages fix security vulnerabilities","details":"The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x \nbefore 5.20.7 might allow remote attackers to conduct SQL injection attacks \nvia vectors related to incorrect quoting. (CVE-2016-7405)\n\nCross Site Scripting vulnerability in test script (CVE-2016-4855)\n","modified":"2026-04-16T06:25:28.352831076Z","published":"2016-11-03T22:53:34Z","upstream":["CVE-2016-4855","CVE-2016-7405"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0363.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=19307"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2016/09/15/1"},{"type":"WEB","url":"http://lwn.net/Alerts/700508/"},{"type":"WEB","url":"http://lwn.net/Vulnerabilities/701151/"}],"affected":[{"package":{"name":"php-adodb","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/php-adodb?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18-5.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0363.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}