CVE-2016-4861
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.12% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- fedoraproject/fedora · zend/zend framework
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN18926672/index.htmlThird Party Advisory, VDB Entry
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000158Third Party Advisory, VDB Entry
- https://framework.zend.com/security/advisory/ZF2016-03Exploit, Technical Description, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/06/msg00012.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2JUKFTI6ABK7ZN7IEAGPCLAHCFANMID2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N27AV6AL6B4KGEP3VIMIHQ5LFAKF5FTU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UR5HXNGIUSSIZKMSZYMPBEPZEZTYFTIT/
- https://security.gentoo.org/glsa/201804-10
- http://jvn.jp/en/jp/JVN18926672/index.htmlThird Party Advisory, VDB Entry
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000158Third Party Advisory, VDB Entry
- https://framework.zend.com/security/advisory/ZF2016-03Exploit, Technical Description, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/06/msg00012.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2JUKFTI6ABK7ZN7IEAGPCLAHCFANMID2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N27AV6AL6B4KGEP3VIMIHQ5LFAKF5FTU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UR5HXNGIUSSIZKMSZYMPBEPZEZTYFTIT/
- https://security.gentoo.org/glsa/201804-10
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.