Опубликовано: 07 июн. 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8
Описание
The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.
Релиз | Статус | Примечание |
---|---|---|
artful | DNE | |
bionic | DNE | |
cosmic | DNE | |
devel | DNE | |
disco | DNE | |
eoan | DNE | |
esm-apps/xenial | needed | |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
esm-infra/focal | DNE | |
focal | DNE |
Показывать по
10
Релиз | Статус | Примечание |
---|---|---|
artful | not-affected | |
bionic | not-affected | |
cosmic | not-affected | |
devel | DNE | |
disco | DNE | |
eoan | DNE | |
esm-apps/bionic | not-affected | |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | DNE | |
focal | DNE |
Показывать по
10
EPSS
Процентиль: 78%
0.01232
Низкий
7.5 High
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
CVSS3: 9.8
nvd
больше 9 лет назад
The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.
CVSS3: 9.8
debian
больше 9 лет назад
The PDO adapters in Zend Framework before 1.12.16 do not filer null by ...
CVSS3: 9.8
github
больше 3 лет назад
Zend Framework SQL injection vector using null byte for PDO
EPSS
Процентиль: 78%
0.01232
Низкий
7.5 High
CVSS2
9.8 Critical
CVSS3