CVE-2014-4914

The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
zendzend_framework
𝑥
< 1.12.7
debiandebian_linux
7.0
debiandebian_linux
8.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
zendframework
lucid
ignored
precise
dne
saucy
dne
trusty
dne
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
php-ZendFramework
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Auth-Adapter-Ldap
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Cache-Backend-Apc
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Cache-Backend-Libmemcached
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Cache-Backend-Memcached
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Captcha
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Db-Adapter-Mysqli
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Db-Adapter-Pdo
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Db-Adapter-Pdo-Mssql
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Db-Adapter-Pdo-Mysql
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Db-Adapter-Pdo-Pgsql
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Dojo
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Feed
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Ldap
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Pdf
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Search-Lucene
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Serializer-Adapter-Igbinary
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Services
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-Soap
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-demos
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-extras
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed
php-ZendFramework-full
Amazon Linux 1
0:1.12.7-1.9.amzn1
fixed