CVE-2016-7405
Summary
| CVE | CVE-2016-7405 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-10-03 18:59:14 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting. |
Risk And Classification
Primary CVSS: v3.0 9.8 CRITICAL from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.031010000 probability, percentile 0.868890000 (date 2026-05-07)
Problem Types: CWE-89 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adodb Project | Adodb | 5.00 | beta | All | All |
| Application | Adodb Project | Adodb | 5.01 | beta | All | All |
| Application | Adodb Project | Adodb | 5.02 | All | All | All |
| Application | Adodb Project | Adodb | 5.02 | a | All | All |
| Application | Adodb Project | Adodb | 5.03 | All | All | All |
| Application | Adodb Project | Adodb | 5.04 | All | All | All |
| Application | Adodb Project | Adodb | 5.04 | a | All | All |
| Application | Adodb Project | Adodb | 5.05 | All | All | All |
| Application | Adodb Project | Adodb | 5.06 | All | All | All |
| Application | Adodb Project | Adodb | 5.06 | a | All | All |
| Application | Adodb Project | Adodb | 5.07 | All | All | All |
| Application | Adodb Project | Adodb | 5.08 | All | All | All |
| Application | Adodb Project | Adodb | 5.08 | a | All | All |
| Application | Adodb Project | Adodb | 5.09 | All | All | All |
| Application | Adodb Project | Adodb | 5.09 | a | All | All |
| Application | Adodb Project | Adodb | 5.10 | All | All | All |
| Application | Adodb Project | Adodb | 5.11 | All | All | All |
| Application | Adodb Project | Adodb | 5.12 | All | All | All |
| Application | Adodb Project | Adodb | 5.13 | All | All | All |
| Application | Adodb Project | Adodb | 5.14 | All | All | All |
| Application | Adodb Project | Adodb | 5.15 | All | All | All |
| Application | Adodb Project | Adodb | 5.16 | All | All | All |
| Application | Adodb Project | Adodb | 5.16 | a | All | All |
| Application | Adodb Project | Adodb | 5.17 | All | All | All |
| Application | Adodb Project | Adodb | 5.18 | All | All | All |
| Application | Adodb Project | Adodb | 5.18 | a | All | All |
| Application | Adodb Project | Adodb | 5.19 | All | All | All |
| Application | Adodb Project | Adodb | 5.20.0 | All | All | All |
| Application | Adodb Project | Adodb | 5.20.1 | All | All | All |
| Application | Adodb Project | Adodb | 5.20.2 | All | All | All |
| Application | Adodb Project | Adodb | 5.20.3 | All | All | All |
| Application | Adodb Project | Adodb | 5.20.4 | All | All | All |
| Application | Adodb Project | Adodb | 5.20.5 | All | All | All |
| Application | Adodb Project | Adodb | 5.20.6 | All | All | All |
| Operating System | Fedoraproject | Fedora | 25 | All | All | All |
| Application | Php | Php | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 25 Update: php-adodb-5.20.6-2.fc25 - package-announce - Fedora Mailing-Lists | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| CVE-2016-7405: ADOdb qstr() method does not quote properly with PDO · Issue #226 · ADOdb/ADOdb · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Patch |
| ADOdb CVE-2016-7405 SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory |
| oss-security - ADOdb PDO driver: incorrect quoting may allow SQL injection | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Patch, Release Notes |
| oss-security - Re: ADOdb PDO driver: incorrect quoting may allow SQL injection | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Patch, Release Notes |
| ADOdb: Multiple vulnerabilities (GLSA 201701-59) — Gentoo Security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| ADOdb/changelog.md at v5.20.7 · ADOdb/ADOdb · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Patch, Release Notes, Vendor Advisory |
| PDO: fix incorrect quoting allowing SQL injection · ADOdb/ADOdb@bd9eca9 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Patch, Vendor Advisory |
| [SECURITY] Fedora 25 Update: php-adodb-5.20.6-2.fc25 - package-announce - Fedora Mailing-Lists | MITRE | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710424 Gentoo Linux ADOdb Multiple Vulnerabilities (GLSA 201701-59)