Description
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.
Remediation
References
Related Vulnerabilities
Apache HTTP Server Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2007-6420)
Magento Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-7923)
WordPress Plugin McAvoy Cross-Site Scripting (0.1.0)
e107 Inadequate Encryption Strength Vulnerability (CVE-2021-27885)
WordPress Plugin WP Easy Stats 'homep' Parameter Remote File Include (1.8)