CVE-2014-8089
17.02.2020, 22:15
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
Vendor | Product | Version |
---|---|---|
zend | zend_framework | 𝑥 < 1.12.9 |
zend | zend_framework | 2.2.0 ≤ 𝑥 < 2.2.8 |
zend | zend_framework | 2.3.0 ≤ 𝑥 < 2.3.3 |
redhat | enterprise_linux | 6.0 |
redhat | enterprise_linux | 7.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
zend-framework |
| ||||||||||||||||||||||||||||||||||||||||||
zendframework |
|
References