First published: Tue Nov 26 2019(Updated: )
SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zend Zend Framework | >=1.11.0<1.11.6 | |
Zend Zend Framework | >=1.10.0<1.10.9 | |
PHP PHP | <5.3.6 | |
Debian Debian Linux | =8.0 | |
debian/zendframework |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1939 is a SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.
CVE-2011-1939 has a severity rating of 9.8 (Critical).
Zend Framework versions 1.10.0 to 1.10.9 and 1.11.0 to 1.11.6, and PHP versions up to 5.3.6 are affected by CVE-2011-1939.
The Common Weakness Enumeration (CWE) ID for CVE-2011-1939 is CWE-89 (SQL Injection).
To fix CVE-2011-1939, it is recommended to upgrade Zend Framework to version 1.10.9 or 1.11.6 and PHP to a version higher than 5.3.6.