CVE-2014-8089

critical

Description

SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.

References

http://framework.zend.com/security/advisory/ZF2014-06

http://seclists.org/oss-sec/2014/q4/276

http://www.securityfocus.com/bid/70011

https://bugzilla.redhat.com/show_bug.cgi?id=1151277

Details

Source: MITRE

Published: 2020-02-17

Updated: 2020-02-20

Type: CWE-89

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL