SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
{
"binaries": [
{
"binary_version": "1.11.11-0ubuntu3.16.04.1",
"binary_name": "libzend-framework-php"
},
{
"binary_version": "1.11.11-0ubuntu3.16.04.1",
"binary_name": "libzend-framework-zendx-php"
},
{
"binary_version": "1.11.11-0ubuntu3.16.04.1",
"binary_name": "zend-framework"
},
{
"binary_version": "1.11.11-0ubuntu3.16.04.1",
"binary_name": "zend-framework-bin"
}
]
}