SQL injection - Code In zendframework/zend-db
Description
Zend Framework SQL injection vulnerability SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 2.0.99, 2.1.99, 2.2.8, 2.3.3 | ||
packagist | 2.0.99, 2.1.99, 2.2.8, 2.3.3 | ||
packagist | 1.12.9 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6. 7. 8.