First published: Tue Jun 07 2016(Updated: )
The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zend Zend Framework | <=1.12.15 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
composer/zendframework/zendframework1 | <1.12.16 | 1.12.16 |
<=1.12.15 | ||
=7.0 | ||
=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.