Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

github логотип

GHSA-w476-322c-wpvm

около 1 месяца назад

SQL injection in pdo_firebird via NUL bytes in quoted strings

EPSS: Низкий
ubuntu логотип

CVE-2025-14179

около 1 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2025-14179

около 1 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2025-14179

около 1 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2025-14179

около 1 месяца назад

SQL injection in pdo_firebird via NUL bytes in quoted strings

EPSS: Низкий
debian логотип

CVE-2025-14179

около 1 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2037-1

около 1 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1958-1

около 1 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1957-1

около 1 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20745-1

около 1 месяца назад

Security update for php8

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-w476-322c-wpvm

SQL injection in pdo_firebird via NUL bytes in quoted strings

0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2025-14179

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2025-14179

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.

CVSS3: 8.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-14179

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2025-14179

SQL injection in pdo_firebird via NUL bytes in quoted strings

0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-14179

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2037-1

Security update for php8

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1958-1

Security update for php8

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1957-1

Security update for php8

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20745-1

Security update for php8

около 1 месяца назад

Уязвимостей на страницу