SQL injection - Code In zendframework/zendframework1
Description
Zend Framework SQL injection vector using null byte for PDO The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 1.12.16 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6.