Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-8088

Опубликовано: 22 окт. 2014
Источник: debian
EPSS Низкий

Описание

The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zendframeworkfixed1.12.9+dfsg-1package

Примечания

  • http://framework.zend.com/security/advisory/ZF2014-05

EPSS

Процентиль: 69%
0.00608
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind.

nvd
больше 11 лет назад

The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind.

github
больше 3 лет назад

Zend Access Restriction Bypass

EPSS

Процентиль: 69%
0.00608
Низкий