Vulnerabilities
Vulnerable Software
Zend:  Security Vulnerabilities
SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.
CVSS Score
9.8
EPSS Score
0.085
Published
2019-11-26
Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.
CVSS Score
9.8
EPSS Score
0.004
Published
2019-10-25
Zend.To version Prior to 5.15-1 contains a Cross Site Scripting (XSS) vulnerability in The verify.php page that can result in An attacker could execute arbitrary Javascript code in the context of the victim's browser.. This attack appear to be exploitable via HTTP POST request. This vulnerability appears to have been fixed in 5.16-1 Beta.
CVSS Score
6.1
EPSS Score
0.003
Published
2018-12-20
Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455.
CVSS Score
6.1
EPSS Score
0.045
Published
2018-04-19
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
CVSS Score
9.8
EPSS Score
0.034
Published
2017-12-29
Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key.
CVSS Score
7.5
EPSS Score
0.002
Published
2017-10-10
Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-site scripting (XSS) or open redirect attacks.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-08-25
Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions without using session validators.
CVSS Score
9.1
EPSS Score
0.003
Published
2017-08-07
Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers.
CVSS Score
8.8
EPSS Score
0.001
Published
2017-06-08
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.
CVSS Score
9.8
EPSS Score
0.04
Published
2017-02-17


Contact Us

Shodan ® - All rights reserved