{"id":"GHSA-v42g-7q2x-cw32","aliases":[],"url":"https://o3.security/vulnerability/GHSA-v42g-7q2x-cw32","summary":"Zendframework1 potential SQL injection vector using null byte for PDO (MsSql, SQLite)","details":"The PDO adapters of Zend Framework 1 do not filter null bytes values in SQL statements. A PDO adapter can treat null bytes in a query as a string terminator, allowing an attacker to add arbitrary SQL following a null byte, and thus create a SQL injection.\n\nWe tested and verified the null byte injection using pdo_dblib (FreeTDS) on a Linux environment to access a remote Microsoft SQL Server, and also tested against and noted the vector against pdo_sqlite.","published":"2024-06-07T22:25:43Z","modified":"2024-12-04T05:41:15.523998Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"zendframework/zendframework1","fixedVersion":"1.12.16"}],"fix":null,"references":[{"type":"WEB","url":"https://framework.zend.com/security/advisory/ZF2015-08"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework1/ZF2015-08.yaml"},{"type":"PACKAGE","url":"https://github.com/zendframework/zf1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:41:15.523998Z"}}