CVE-2014-8089
CRITICALZend Framework < 1.12.9, 2.2.x < 2.2.8, 2.3.x < 2.3.3 - SQL Injection via Null Byte
Title source: llmDescription
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/70011
Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/oss-sec/2014/q4/276
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1151277
Exploit, Vendor Advisory x_refsource_misc
http://framework.zend.com/security/advisory/ZF2014-06
Scores
CVSS v3
9.8
EPSS
0.0255
EPSS Percentile
83.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (9)
fedoraproject/fedora
19
fedoraproject/fedora
20
fedoraproject/fedora
21
redhat/enterprise_linux
6.0
redhat/enterprise_linux
7.0
zend/zend_framework
< 1.12.9
zendframework/zend-db
2.0.0 - 2.0.99Packagist
zendframework/zendframework
2.0.0 - 2.0.99Packagist
zendframework/zendframework1
1.12.0 - 1.12.9Packagist
Published
Feb 17, 2020
Tracked Since
Feb 18, 2026