668
VMScore

CVE-2014-8089

Published: 17/02/2020 Updated: 20/02/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Zend Framework prior to 1.12.9, 2.2.x prior to 2.2.8, and 2.3.x prior to 2.3.3, when using the sqlsrv PHP extension, allows remote malicious users to execute arbitrary SQL commands via a null byte.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zend zend framework

redhat enterprise linux 6.0

redhat enterprise linux 7.0

fedoraproject fedora 19

fedoraproject fedora 20

fedoraproject fedora 21

Vendor Advisories

Debian Bug report logs - #754201 Potential SQL injection in the ORDER implementation of Zend_Db_Select (ZF2014-04) Package: zendframework; Maintainer for zendframework is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Source for zendframework is src:zendframework (PTS, buildd, popcon) Reported by: David ...
Debian Bug report logs - #754201 Potential SQL injection in the ORDER implementation of Zend_Db_Select (ZF2014-04) Package: zendframework; Maintainer for zendframework is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Source for zendframework is src:zendframework (PTS, buildd, popcon) Reported by: David ...
Multiple vulnerabilities were discovered in Zend Framework, a PHP framework Except for CVE-2015-3154, all these issues were already fixed in the version initially shipped with Jessie CVE-2014-2681 Lukas Reschke reported a lack of protection against XML External Entity injection attacks in some functions This fix extends the incomple ...
The (1) Zend_Ldap class in Zend before 1129 and (2) Zend\Ldap component in Zend 2x before 228 and 23x before 233 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind (CVE-2014-8088) The 1129, 228, and 233 releases of the Zend Framework fix an SQL injection ...