CVE-2016-4861

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.
References
Link Resource
http://jvn.jp/en/jp/JVN18926672/index.html Third Party Advisory VDB Entry
http://jvndb.jvn.jp/jvndb/JVNDB-2016-000158 Third Party Advisory VDB Entry
https://framework.zend.com/security/advisory/ZF2016-03 Exploit Technical Description Vendor Advisory
https://lists.debian.org/debian-lts-announce/2018/06/msg00012.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2JUKFTI6ABK7ZN7IEAGPCLAHCFANMID2/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N27AV6AL6B4KGEP3VIMIHQ5LFAKF5FTU/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UR5HXNGIUSSIZKMSZYMPBEPZEZTYFTIT/
https://security.gentoo.org/glsa/201804-10
http://jvn.jp/en/jp/JVN18926672/index.html Third Party Advisory VDB Entry
http://jvndb.jvn.jp/jvndb/JVNDB-2016-000158 Third Party Advisory VDB Entry
https://framework.zend.com/security/advisory/ZF2016-03 Exploit Technical Description Vendor Advisory
https://lists.debian.org/debian-lts-announce/2018/06/msg00012.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2JUKFTI6ABK7ZN7IEAGPCLAHCFANMID2/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N27AV6AL6B4KGEP3VIMIHQ5LFAKF5FTU/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UR5HXNGIUSSIZKMSZYMPBEPZEZTYFTIT/
https://security.gentoo.org/glsa/201804-10
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:zend:zend_framework:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-02-17 02:59

Updated : 2025-04-20 01:37


NVD link : CVE-2016-4861

Mitre link : CVE-2016-4861

CVE.ORG link : CVE-2016-4861


JSON object : View

Products Affected

zend

  • zend_framework

fedoraproject

  • fedora
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')