Zend Framework 1.12.16

CPE Details

Zend Framework 1.12.16
1.12.16
2019-06-18
17h17 +00:00
2019-06-18
17h17 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:zend:zend_framework:1.12.16:*:*:*:*:*:*:*

Informations

Vendor

zend

Product

zend_framework

Version

1.12.16

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2020-29312 2023-04-04 00h00 +00:00 An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The framework does not have a version that surpasses 2.x.x and was deprecated in early 2020.
9.8
Critique
CVE-2012-4451 2020-01-03 15h03 +00:00 Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper.
6.1
Moyen
CVE-2014-4913 2019-12-15 20h24 +00:00 ZF2014-03 has a potential cross site scripting vector in multiple view helpers
6.1
Moyen
CVE-2016-4861 2017-02-16 17h00 +00:00 The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.
9.8
Critique
CVE-2016-6233 2017-02-16 17h00 +00:00 The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [\w]* in a regular expression.
9.8
Critique
CVE-2016-10034 2016-12-30 18h00 +00:00 The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.
9.8
Critique
CVE-2015-5723 2016-06-07 12h00 +00:00 Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.
7.8
Haute