CRITICAL9.8
GHSA-qh9w-r7g5-q939
Zend Framework SQL injection vulnerability
Quick fix
GHSA-qh9w-r7g5-q939 — zendframework/zendframework1: upgrade to the fixed version with the command below.
composer require zendframework/zendframework1:^1.12.9Details
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/zendframework/zendframework1
Introduced in:
1.12.0Fixed in: 1.12.9Fix
composer require zendframework/zendframework1:^1.12.9Packagist/zendframework/zend-db
Introduced in:
2.0.0Fixed in: 2.0.99Fix
composer require zendframework/zend-db:^2.0.99Packagist/zendframework/zend-db
Introduced in:
2.1.0Fixed in: 2.1.99Fix
composer require zendframework/zend-db:^2.1.99Packagist/zendframework/zend-db
Introduced in:
2.2.0Fixed in: 2.2.8Fix
composer require zendframework/zend-db:^2.2.8Packagist/zendframework/zend-db
Introduced in:
2.3.0Fixed in: 2.3.3Fix
composer require zendframework/zend-db:^2.3.3Packagist/zendframework/zendframework
Introduced in:
2.0.0Fixed in: 2.0.99Fix
composer require zendframework/zendframework:^2.0.99Packagist/zendframework/zendframework
Introduced in:
2.1.0Fixed in: 2.1.99Fix
composer require zendframework/zendframework:^2.1.99Packagist/zendframework/zendframework
Introduced in:
2.2.0Fixed in: 2.2.8Fix
composer require zendframework/zendframework:^2.2.8Packagist/zendframework/zendframework
Introduced in:
2.3.0Fixed in: 2.3.3Fix
composer require zendframework/zendframework:^2.3.3References
- https://nvd.nist.gov/vuln/detail/CVE-2014-8089[ADVISORY]
- https://bugzilla.redhat.com/show_bug.cgi?id=1151277[WEB]
- https://framework.zend.com/security/advisory/ZF2014-06[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zend-db/CVE-2014-8089.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework/CVE-2014-8089.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework1/CVE-2014-8089.yaml[WEB]
- http://framework.zend.com/security/advisory/ZF2014-06[WEB]
- http://seclists.org/oss-sec/2014/q4/276[WEB]
- http://www.securityfocus.com/bid/70011[WEB]