VDB
Sign up
CRITICAL9.8

GHSA-2hvh-c5c2-vj85

Zend Framework SQL injection vector using null byte for PDO

Quick fix

GHSA-2hvh-c5c2-vj85 — zendframework/zendframework1: upgrade to the fixed version with the command below.

composer require zendframework/zendframework1:^1.12.16

Details

The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zendframework/zendframework1
Introduced in: 0Fixed in: 1.12.16
Fixcomposer require zendframework/zendframework1:^1.12.16

References