Vulnerabilities > John LIM > Adodb > 4.70

DATE CVE VULNERABILITY TITLE RISK
2006-02-21 CVE-2006-0806 Cross-Site Scripting vulnerability in John LIM Adodb
Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF.
network
john-lim CWE-79
4.3
2006-01-25 CVE-2006-0410 SQL Injection vulnerability in John LIM Adodb 4.66/4.68/4.70
SQL injection vulnerability in ADOdb before 4.71, when using PostgreSQL, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors involving binary strings.
network
low complexity
john-lim
5.0