|
|
| |
|
| |
php-zendframework: multiple vulnerabilities
| Package(s): | php-zendframework |
CVE #(s): | |
| Created: | October 8, 2012 |
Updated: | October 10, 2012 |
| Description: |
From the ZendFramework advisories [1], [2]:
[1] The default error handling view script generated using Zend_Tool failed to escape request parameters when run in the "development" configuration environment, providing a potential XSS attack vector.
[2] Developers using non-ASCII-compatible encodings in conjunction with the MySQL PDO driver of PHP may be vulnerable to SQL injection attacks. Developers using ASCII-compatible encodings like UTF8 or latin1 are not affected by this PHP issue. |
| Alerts: |
|
( Log in to post comments)
|
|
|