Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-4861

Опубликовано: 17 фев. 2017
Источник: debian

Описание

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zendframeworkfixed1.12.20+dfsg-1package

Примечания

  • http://framework.zend.com/security/advisory/ZF2016-03

  • This security fix can be considered an improvement of the previous ZF2016-02

  • and ZF2014-04 advisories.

  • Fixed by: https://github.com/zendframework/zf1/commit/b1c71dd94296d9000127720c85a7ea9e3b35af4b (1.12.20)

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.

CVSS3: 9.8
nvd
почти 9 лет назад

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.

CVSS3: 9.8
github
больше 3 лет назад

Zend Framework Allows SQL Injection