Количество 11
Количество 11
BDU:2026-01640
Уязвимость драйвера PDO для СУБД Firebird интерпретатора языка программирования PHP, позволяющая нарушителю осуществлять SQL-инъекции
CVE-2025-14179
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.
CVE-2025-14179
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.
CVE-2025-14179
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.
CVE-2025-14179
SQL injection in pdo_firebird via NUL bytes in quoted strings
CVE-2025-14179
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...
GHSA-w476-322c-wpvm
SQL injection in pdo_firebird via NUL bytes in quoted strings
SUSE-SU-2026:2037-1
Security update for php8
SUSE-SU-2026:1958-1
Security update for php8
SUSE-SU-2026:1957-1
Security update for php8
openSUSE-SU-2026:20745-1
Security update for php8
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-01640 Уязвимость драйвера PDO для СУБД Firebird интерпретатора языка программирования PHP, позволяющая нарушителю осуществлять SQL-инъекции | CVSS3: 8.1 | 0% Низкий | 6 месяцев назад | |
CVE-2025-14179 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2025-14179 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements. | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
CVE-2025-14179 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2025-14179 SQL injection in pdo_firebird via NUL bytes in quoted strings | 0% Низкий | 3 месяца назад | ||
CVE-2025-14179 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ... | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
GHSA-w476-322c-wpvm SQL injection in pdo_firebird via NUL bytes in quoted strings | 0% Низкий | 3 месяца назад | ||
SUSE-SU-2026:2037-1 Security update for php8 | 2 месяца назад | |||
SUSE-SU-2026:1958-1 Security update for php8 | 2 месяца назад | |||
SUSE-SU-2026:1957-1 Security update for php8 | 2 месяца назад | |||
openSUSE-SU-2026:20745-1 Security update for php8 | 3 месяца назад |
Уязвимостей на страницу