CVE-2014-8089
CVE-2014-8089
9.8
CriticalPublished:
Last updated:
Source:cve@mitre.org
Modified
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Description
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
References
cve@mitre.org
http://seclists.org/oss-sec/2014/q4/276cve@mitre.org
http://www.securityfocus.com/bid/70011cve@mitre.org
https://bugzilla.redhat.com/show_bug.cgi?id=1151277af854a3a-2127-422b-91ae-364da2661108
http://framework.zend.com/security/advisory/ZF2014-06af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/oss-sec/2014/q4/276af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/70011af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.redhat.com/show_bug.cgi?id=1151277