CVE-2014-4914: SQL Injection
Published Dec 29, 2017
·Updated
The ZendDbSelect::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
Affected Software
4 affected components
debian/zendframework
Zend Zend Framework<1.12.7
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Event History
Dec 29, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4914?
The severity of CVE-2014-4914 is critical with a severity value of 9.8.
2
What is the affected software for CVE-2014-4914?
The affected software for CVE-2014-4914 includes Zend Framework versions before 1.12.7 and Debian Linux versions 7.0 and 8.0.
3
How does CVE-2014-4914 impact the affected software?
CVE-2014-4914 allows remote attackers to conduct SQL injection attacks via unspecified vectors in the Zend_Db_Select::order function.
4
Are there any remedies available for CVE-2014-4914?
No remedies are available for CVE-2014-4914.
5
Where can I find more information about CVE-2014-4914?
You can find more information about CVE-2014-4914 in the following references: [link1], [link2], [link3].