CVE-2016-6233: SQL Injection
Potential SQL injection in ORDER and GROUP statements of ZendDbSelect
Other sources
The (1) order and (2) group methods in ZendDbSelect in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [\w] in a regular expression.
The (1) order and (2) group methods in ZendDbSelect in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [\w] in a regular expression.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6233?
CVE-2016-6233 is classified as a medium severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2016-6233?
To fix CVE-2016-6233, upgrade your Zend Framework version to 1.12.19 or later.
What types of attacks can be executed due to CVE-2016-6233?
CVE-2016-6233 allows attackers to perform SQL injection attacks through the order and group methods.
What software versions are affected by CVE-2016-6233?
CVE-2016-6233 affects all versions of Zend Framework prior to 1.12.19.
Is this vulnerability specific to any operating systems?
CVE-2016-6233 can affect any operating system running the vulnerable Zend Framework version, including Fedora.