First published: Wed Feb 18 2015(Updated: )
Potential SQL injection in PostgreSQL Zend\Db adapter
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/zendframework/zend-db | >=2.0.0<2.0.99>=2.1.0<2.1.99>=2.2.0<2.2.10>=2.3.0<2.3.5 | |
composer/zendframework/zendframework | >=2.0.0<2.0.99>=2.1.0<2.1.99>=2.2.0<2.2.10>=2.3.0<2.3.5 | |
Zend Framework | <2.2.10 | |
Zend Framework | >=2.3.0<2.3.5 | |
composer/zendframework/zendframework | >=2.3.0<2.3.5 | 2.3.5 |
composer/zendframework/zendframework | <2.2.10 | 2.2.10 |
composer/zendframework/zend-db | >=2.3.0<2.3.5 | 2.3.5 |
composer/zendframework/zend-db | <2.2.10 | 2.2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0270 has a high severity rating due to its potential for SQL injection vulnerabilities.
To fix CVE-2015-0270, update your Zend Framework to version 2.2.10 or 2.3.5 or later.
CVE-2015-0270 affects all versions of Zend Framework before 2.2.10 and 2.3.x before 2.3.5.
CVE-2015-0270 can lead to unauthorized access and manipulation of data in PostgreSQL databases due to SQL injection.
CVE-2015-0270 is not limited to specific platforms but primarily affects applications using the vulnerable Zend Framework.