CVE-2015-0270: SQL Injection
Published Feb 18, 2015
·Updated
Potential SQL injection in PostgreSQL Zend\Db adapter
Affected Software
8 affected componentsFixes available
composer/zendframework/zend-db>=2.0.0, <2.0.99, >=2.1.0, <2.1.99, >=2.2.0, <2.2.10, >=2.3.0, <2.3.5
composer/zendframework/zendframework>=2.0.0, <2.0.99, >=2.1.0, <2.1.99, >=2.2.0, <2.2.10, >=2.3.0, <2.3.5
Zend Framework<2.2.10
Zend Framework>=2.3.0<2.3.5
composer/zendframework/zend-db>=2.3.0<2.3.5
2.3.5
composer/zendframework/zend-db<2.2.10
2.2.10
composer/zendframework/zendframework>=2.3.0<2.3.5
2.3.5
composer/zendframework/zendframework<2.2.10
2.2.10
Event History
Feb 18, 2015
Advisory Published
07:15 PM
Oct 25, 2019
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2015-0270?
CVE-2015-0270 has a high severity rating due to its potential for SQL injection vulnerabilities.
2
How do I fix CVE-2015-0270?
To fix CVE-2015-0270, update your Zend Framework to version 2.2.10 or 2.3.5 or later.
3
Which versions of Zend Framework are affected by CVE-2015-0270?
CVE-2015-0270 affects all versions of Zend Framework before 2.2.10 and 2.3.x before 2.3.5.
4
What impact does CVE-2015-0270 have on PostgreSQL databases?
CVE-2015-0270 can lead to unauthorized access and manipulation of data in PostgreSQL databases due to SQL injection.
5
Is CVE-2015-0270 limited to specific platforms?
CVE-2015-0270 is not limited to specific platforms but primarily affects applications using the vulnerable Zend Framework.