Описание
Zend Framework SQL injection vulnerability
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-8089
- https://bugzilla.redhat.com/show_bug.cgi?id=1151277
- https://framework.zend.com/security/advisory/ZF2014-06
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zend-db/CVE-2014-8089.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework/CVE-2014-8089.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework1/CVE-2014-8089.yaml
- http://framework.zend.com/security/advisory/ZF2014-06
- http://seclists.org/oss-sec/2014/q4/276
- http://www.securityfocus.com/bid/70011
Пакеты
zendframework/zendframework1
>= 1.12.0, < 1.12.9
1.12.9
zendframework/zend-db
>= 2.0.0, < 2.0.99
2.0.99
zendframework/zend-db
>= 2.1.0, < 2.1.99
2.1.99
zendframework/zend-db
>= 2.2.0, < 2.2.8
2.2.8
zendframework/zend-db
>= 2.3.0, < 2.3.3
2.3.3
zendframework/zendframework
>= 2.0.0, < 2.0.99
2.0.99
zendframework/zendframework
>= 2.1.0, < 2.1.99
2.1.99
zendframework/zendframework
>= 2.2.0, < 2.2.8
2.2.8
zendframework/zendframework
>= 2.3.0, < 2.3.3
2.3.3
Связанные уязвимости
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x bef ...