Vulnerabilities > John LIM > Adodb > 4.70
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-02-21 | CVE-2006-0806 | Cross-Site Scripting vulnerability in John LIM Adodb Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF. | 4.3 |
2006-01-25 | CVE-2006-0410 | SQL Injection vulnerability in John LIM Adodb 4.66/4.68/4.70 SQL injection vulnerability in ADOdb before 4.71, when using PostgreSQL, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors involving binary strings. | 5.0 |