Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2011-1939SQL Injection in Framework

CWE-89SQL Injection6 documents5 sources
Severity
9.8CRITICALNVD
EPSS
5.6%
top 9.71%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedNov 26
Latest updateApr 22

Description

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDzend/zend_framework1.10.01.10.9+1
CVEListV5zendframework_php/phpbefore 5.3.6
CVEListV5zendframework_php/zendframework1.10.x before 1.10.9, 1.11.x before 1.11.6+1
NVDphp/php< 5.3.6

Also affects: Debian Linux 8.0

🔴Vulnerability Details

2
GHSA
GHSA-v2wg-2jpv-87h6: SQL injection vulnerability in Zend Framework 12022-04-22
CVEList
CVE-2011-1939: SQL injection vulnerability in Zend Framework 12019-11-26

💥Exploits & PoCs

1
Exploit-DB
Zend Framework 1.11.4 - 'PDO_MySql' Security Bypass2011-05-19

💬Community

1
Bugzilla
CVE-2011-1939 php-ZendFramework: potential SQL injection vector when using PDO_MySql (ZF2011-02)2011-05-31
CVE-2011-1939 — SQL Injection in Zend Framework | cvebase