The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libphp-adodbUpgrade cacti | Jul 30, 2024 | Jan 9, 2006 |
| Freebsd | — | Upgrade lifetype | Dec 10, 2025 | Apr 27, 2006 |
| Gentoo Linux | — | Upgrade net-analyzer/cacti. | Oct 30, 2017 | Jan 9, 2006 |
| Moodle | — | Upgrade to the latest version of Moodle | Nov 7, 2019 | Jan 9, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub