The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "5.00-beta"
},
{
"introduced": "0"
},
{
"last_affected": "5.01-beta"
},
{
"introduced": "0"
},
{
"last_affected": "5.02"
},
{
"introduced": "0"
},
{
"last_affected": "5.02-a"
},
{
"introduced": "0"
},
{
"last_affected": "5.03"
},
{
"introduced": "0"
},
{
"last_affected": "5.04"
},
{
"introduced": "0"
},
{
"last_affected": "5.04-a"
},
{
"introduced": "0"
},
{
"last_affected": "5.05"
},
{
"introduced": "0"
},
{
"last_affected": "5.06"
},
{
"introduced": "0"
},
{
"last_affected": "5.06-a"
},
{
"introduced": "0"
},
{
"last_affected": "5.07"
},
{
"introduced": "0"
},
{
"last_affected": "5.08"
},
{
"introduced": "0"
},
{
"last_affected": "5.08-a"
},
{
"introduced": "0"
},
{
"last_affected": "5.09"
},
{
"introduced": "0"
},
{
"last_affected": "5.09-a"
},
{
"introduced": "0"
},
{
"last_affected": "5.10"
},
{
"introduced": "0"
},
{
"last_affected": "5.11"
},
{
"introduced": "0"
},
{
"last_affected": "5.12"
},
{
"introduced": "0"
},
{
"last_affected": "5.13"
},
{
"introduced": "0"
},
{
"last_affected": "5.14"
},
{
"introduced": "0"
},
{
"last_affected": "5.15"
},
{
"introduced": "0"
},
{
"last_affected": "5.16"
},
{
"introduced": "0"
},
{
"last_affected": "5.16-a"
},
{
"introduced": "0"
},
{
"last_affected": "5.17"
},
{
"introduced": "0"
},
{
"last_affected": "5.18"
},
{
"introduced": "0"
},
{
"last_affected": "5.18-a"
},
{
"introduced": "0"
},
{
"last_affected": "5.19"
},
{
"introduced": "0"
},
{
"last_affected": "5.20.0"
},
{
"introduced": "0"
},
{
"last_affected": "5.20.1"
},
{
"introduced": "0"
},
{
"last_affected": "5.20.2"
},
{
"introduced": "0"
},
{
"last_affected": "5.20.3"
},
{
"introduced": "0"
},
{
"last_affected": "5.20.4"
},
{
"introduced": "0"
},
{
"last_affected": "5.20.5"
},
{
"introduced": "0"
},
{
"last_affected": "5.20.6"
}
]
}