The implementation of the ORDER BY SQL statement in ZendDbSelect of Zend Framework 1 contains a potential SQL injection when the query string passed contains parentheses (CVE-2014-4914).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2014-0311.json"