<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>123442</bug_id>
          
          <creation_ts>2006-02-19 21:35 0000</creation_ts>
          <short_desc>dev-php/adodb: cross site scripting vulnerability</short_desc>
          <delta_ts>2009-01-11 19:05:36 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.gulftech.org/?node=research&amp;article_id=00101-02182006</bug_file_loc>
          <status_whiteboard>B4 [noglsa] DerCorny</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>dercorny@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>php-bugs@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-02-19 21:35:52 0000</bug_when>
            <thetext>There are several Cross Site Scripting issues in ADOdb versions 4.71 and possibly earlier that may allow for an attacker to render malicious client side code in the victim&apos;s browser. 
 
if (isset($_GET[$next_page])) {
        $_SESSION[$curr_page] = $_GET[$next_page];
}
if (empty($_SESSION[$curr_page])) $_SESSION[$curr_page] = 1; ## at first page
                
$this-&gt;curr_page = $_SESSION[$curr_page];</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-02-19 21:36:53 0000</bug_when>
            <thetext>web-apps team please bump, thx.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2006-02-20 04:00:50 0000</bug_when>
            <thetext>Not webapps ;) Also, there&apos;s no update available now, 4.71 is still latest version upstream.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-02-23 07:50:32 0000</bug_when>
            <thetext>4.72 seems to be released, http://sourceforge.net/project/showfiles.php?group_id=42718&amp;package_id=34890&amp;release_id=395252</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>chtekk@gentoo.org</who>
            <bug_when>2006-02-23 09:27:48 0000</bug_when>
            <thetext>Thanks for the notification, dev-php/adodb-4.72 is now in the tree.
Best regards, CHTEKK.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-02-23 09:30:13 0000</bug_when>
            <thetext>arches pls test and mark stable, thx</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2006-02-23 09:56:18 0000</bug_when>
            <thetext>Stefan, please add arches when setting [stable]
Target KEYWORDS=&quot;alpha amd64 ia64 ppc ppc64 ~sparc x86&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2006-02-23 12:54:12 0000</bug_when>
            <thetext>stable on ppc64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>halcy0n@gentoo.org</who>
            <bug_when>2006-02-24 20:23:09 0000</bug_when>
            <thetext>x86 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2006-02-26 06:37:03 0000</bug_when>
            <thetext>Stable on alpha + ia64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2006-02-26 10:50:31 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2006-02-27 11:32:12 0000</bug_when>
            <thetext>amd64 stable. happy voting!</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-02-28 08:11:51 0000</bug_when>
            <thetext>Hehe thx blubb, i tend to say yes</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2006-03-03 09:50:54 0000</bug_when>
            <thetext>I tend to say no... Could be convinced otherwise if a major portage package made use of this...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2006-03-06 13:37:52 0000</bug_when>
            <thetext>RDEPs:
dev-php4/adodb-ext-503
dev-php5/adodb-ext-503
net-analyzer/acid-0.9.6_beta23
net-analyzer/acid-0.9.6_beta23-r1
net-analyzer/base-1.2.2
net-analyzer/base-1.2.2-r1
net-www/bugport-1.146

No real XSS victim here, I vote no.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>taviso@gentoo.org</who>
            <bug_when>2006-03-06 13:39:34 0000</bug_when>
            <thetext>agree with Koon, no major target for Xss, voting NO and closing.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>