SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
| Software | From | Fixed in |
|---|---|---|
| zend / zend_framework | - | 1.12.9 |
| zend / zend_framework | 2.3.0 | 2.3.3 |
| zend / zend_framework | 2.2.0 | 2.2.8 |
| redhat / enterprise_linux | 7.0 | 7.0.x |
| redhat / enterprise_linux | 6.0 | 6.0.x |
| fedoraproject / fedora | 20 | 20.x |
| fedoraproject / fedora | 21 | 21.x |
| fedoraproject / fedora | 19 | 19.x |
zendframework / zendframework1
|
1.12.0 | 1.12.9 |
zendframework / zend-db
|
2.0.0 | 2.0.99 |
zendframework / zend-db
|
2.1.0 | 2.1.99 |
zendframework / zend-db
|
2.2.0 | 2.2.8 |
zendframework / zend-db
|
2.3.0 | 2.3.3 |
zendframework / zendframework
|
2.0.0 | 2.0.99 |
zendframework / zendframework
|
2.1.0 | 2.1.99 |
zendframework / zendframework
|
2.2.0 | 2.2.8 |
zendframework / zendframework
|
2.3.0 | 2.3.3 |