Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 18

Количество 18

fstec логотип

BDU:2026-01640

7 месяцев назад

Уязвимость драйвера PDO для СУБД Firebird интерпретатора языка программирования PHP, позволяющая нарушителю осуществлять SQL-инъекции

CVSS3: 8.1
EPSS: Низкий
redos логотип

ROS-20260901-80-0016

14 дней назад

Уязвимость php 8.5

CVSS3: 8.1
EPSS: Низкий
redos логотип

ROS-20260901-80-0015

14 дней назад

Уязвимость php 8.4

CVSS3: 8.1
EPSS: Низкий
redos логотип

ROS-20260901-80-0014

14 дней назад

Уязвимость php 8.3

CVSS3: 8.1
EPSS: Низкий
redos логотип

ROS-20260901-80-0013

14 дней назад

Уязвимость php

CVSS3: 8.1
EPSS: Низкий
redos логотип

ROS-20260901-73-0012

14 дней назад

Уязвимость php 8.4

CVSS3: 8.1
EPSS: Низкий
redos логотип

ROS-20260901-73-0011

14 дней назад

Уязвимость php 8.3

CVSS3: 8.1
EPSS: Низкий
redos логотип

ROS-20260901-73-0010

14 дней назад

Уязвимость php

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2025-14179

4 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2025-14179

4 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2025-14179

4 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2025-14179

4 месяца назад

SQL injection in pdo_firebird via NUL bytes in quoted strings

EPSS: Низкий
debian логотип

CVE-2025-14179

4 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-w476-322c-wpvm

4 месяца назад

SQL injection in pdo_firebird via NUL bytes in quoted strings

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2037-1

4 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1958-1

4 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1957-1

4 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20745-1

4 месяца назад

Security update for php8

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-01640

Уязвимость драйвера PDO для СУБД Firebird интерпретатора языка программирования PHP, позволяющая нарушителю осуществлять SQL-инъекции

CVSS3: 8.1
0%
Низкий
7 месяцев назад
redos логотип
ROS-20260901-80-0016

Уязвимость php 8.5

CVSS3: 8.1
0%
Низкий
14 дней назад
redos логотип
ROS-20260901-80-0015

Уязвимость php 8.4

CVSS3: 8.1
0%
Низкий
14 дней назад
redos логотип
ROS-20260901-80-0014

Уязвимость php 8.3

CVSS3: 8.1
0%
Низкий
14 дней назад
redos логотип
ROS-20260901-80-0013

Уязвимость php

CVSS3: 8.1
0%
Низкий
14 дней назад
redos логотип
ROS-20260901-73-0012

Уязвимость php 8.4

CVSS3: 8.1
0%
Низкий
14 дней назад
redos логотип
ROS-20260901-73-0011

Уязвимость php 8.3

CVSS3: 8.1
0%
Низкий
14 дней назад
redos логотип
ROS-20260901-73-0010

Уязвимость php

CVSS3: 8.1
0%
Низкий
14 дней назад
ubuntu логотип
CVE-2025-14179

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.

CVSS3: 9.8
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-14179

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.

CVSS3: 8.1
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-14179

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.

CVSS3: 9.8
0%
Низкий
4 месяца назад
msrc логотип
CVE-2025-14179

SQL injection in pdo_firebird via NUL bytes in quoted strings

0%
Низкий
4 месяца назад
debian логотип
CVE-2025-14179

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 9.8
0%
Низкий
4 месяца назад
github логотип
GHSA-w476-322c-wpvm

SQL injection in pdo_firebird via NUL bytes in quoted strings

0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2037-1

Security update for php8

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1958-1

Security update for php8

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1957-1

Security update for php8

4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20745-1

Security update for php8

4 месяца назад

Уязвимостей на страницу