Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-4861

Опубликовано: 17 фев. 2017
Источник: debian
EPSS Низкий

Описание

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zendframeworkfixed1.12.20+dfsg-1package

Примечания

  • http://framework.zend.com/security/advisory/ZF2016-03

  • This security fix can be considered an improvement of the previous ZF2016-02

  • and ZF2014-04 advisories.

  • Fixed by: https://github.com/zendframework/zf1/commit/b1c71dd94296d9000127720c85a7ea9e3b35af4b (1.12.20)

EPSS

Процентиль: 90%
0.04124
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.

CVSS3: 9.8
nvd
больше 9 лет назад

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.

CVSS3: 9.8
github
больше 4 лет назад

Zend Framework Allows SQL Injection

EPSS

Процентиль: 90%
0.04124
Низкий