5
CVSSv2

CVE-2014-8088

Published: 22/10/2014 Updated: 04/11/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The (1) Zend_Ldap class in Zend prior to 1.12.9 and (2) Zend\Ldap component in Zend 2.x prior to 2.2.8 and 2.3.x prior to 2.3.3 allows remote malicious users to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind.

Vulnerable Product Search on Vulmon Subscribe to Product

zend zend framework

zend zend framework 1.12.0

zend zend framework 2.01

zend zend framework 2.0.0

zend zend framework 1.12.5

zend zend framework 1.12.3

zend zend framework 2.2.3

zend zend framework 2.3.2

zend zend framework 2.3.1

zend zend framework 2.2.5

zend zend framework 2.2.6

zend zend framework 2.2.7

zend zend framework 1.12.2

zend zend framework 1.12.1

zend zend framework 2.2.2

zend zend framework 2.2.4

zend zend framework 2.3.0

Vendor Advisories

Debian Bug report logs - #754201 Potential SQL injection in the ORDER implementation of Zend_Db_Select (ZF2014-04) Package: zendframework; Maintainer for zendframework is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Source for zendframework is src:zendframework (PTS, buildd, popcon) Reported by: David ...
Debian Bug report logs - #754201 Potential SQL injection in the ORDER implementation of Zend_Db_Select (ZF2014-04) Package: zendframework; Maintainer for zendframework is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Source for zendframework is src:zendframework (PTS, buildd, popcon) Reported by: David ...
Multiple vulnerabilities were discovered in Zend Framework, a PHP framework Except for CVE-2015-3154, all these issues were already fixed in the version initially shipped with Jessie CVE-2014-2681 Lukas Reschke reported a lack of protection against XML External Entity injection attacks in some functions This fix extends the incomple ...
The (1) Zend_Ldap class in Zend before 1129 and (2) Zend\Ldap component in Zend 2x before 228 and 23x before 233 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind (CVE-2014-8088) The 1129, 228, and 233 releases of the Zend Framework fix an SQL injection ...