ZeroHour

CVE-2016-4861

PoC
CVSS 3.0
9.8 critical
EPSS
4%p90
Published
()
Modified
Description

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.

Vendors
fedoraprojectzend
Products
fedora, zend framework
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.