CVE-2016-7405

critical
Published 2016-10-03 · Modified 2024-02-21
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

ADOdb Library SQL Injection

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-7405

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/ADOdb/ADOdb/issues/226

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/ADOdb/ADOdb/commit/bd9eca9f40220f9918ec3cc7ae9ef422b3e448b8

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/ADOdb/ADOdb/blob/v5.20.7/docs/changelog.md

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.openwall.com/lists/oss-security/2016/09/15/1

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.openwall.com/lists/oss-security/2016/09/07/8

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed5.20.6-1
debian debianbullseyefixed5.20.6-1
debian debianforkyfixed5.20.6-1
debian debiansidfixed5.20.6-1
debian debiantrixiefixed5.20.6-1
fedora fedora25affected

Package impact

EcosystemPackageVulnerableFixed
php Packagistadodb/adodb-php>=5.0,<5.20.75.20.7

Application impact

VendorProductVersionsFixed
adodb_projectadodb5.00
adodb_projectadodb5.01
adodb_projectadodb5.02
adodb_projectadodb5.03
adodb_projectadodb5.04
adodb_projectadodb5.05
adodb_projectadodb5.06
adodb_projectadodb5.07
adodb_projectadodb5.08
adodb_projectadodb5.09
adodb_projectadodb5.10
adodb_projectadodb5.11
adodb_projectadodb5.12
adodb_projectadodb5.13
adodb_projectadodb5.14
adodb_projectadodb5.15
adodb_projectadodb5.16
adodb_projectadodb5.17
adodb_projectadodb5.18
adodb_projectadodb5.19
adodb_projectadodb5.20.0
adodb_projectadodb5.20.1
adodb_projectadodb5.20.2
adodb_projectadodb5.20.3
adodb_projectadodb5.20.4
adodb_projectadodb5.20.5
adodb_projectadodb5.20.6
php phpphp-

References

CWEs

CWE-89

Verify integrity in audit chain (admin only). AS-IS.