CVE-2016-7405

Source
https://cve.org/CVERecord?id=CVE-2016-7405
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-7405.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-7405
Aliases
Downstream
Published
2016-10-03T18:59:14Z
Modified
2026-05-17T11:55:03Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.

Database specific
{
    "unresolved_ranges": [
        {
            "cpes": [
                "cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "last_affected": "25"
                }
            ],
            "source": "CPE_FIELD",
            "vendor_product": "fedoraproject:fedora"
        }
    ]
}
References

Affected packages