Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-8089

Опубликовано: 17 фев. 2020
Источник: debian
EPSS Низкий

Описание

SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zendframeworkfixed1.12.9+dfsg-1package

Примечания

  • http://framework.zend.com/security/advisory/ZF2014-06

EPSS

Процентиль: 84%
0.0255
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.

CVSS3: 9.8
nvd
больше 6 лет назад

SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.

CVSS3: 9.8
github
больше 2 лет назад

Zend Framework SQL injection vulnerability

EPSS

Процентиль: 84%
0.0255
Низкий