CVE-2014-8089: Fedoraproject Fedora
Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
Affected products
- Fedoraproject Fedora: version 19 only; version 20 only; version 21 only
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only
- Zend Zend Framework: before 1.12.9 (fixed in 1.12.9); from 2.2.0, before 2.2.8 (fixed in 2.2.8); from 2.3.0, before 2.3.3 (fixed in 2.3.3)
Published 2020-02-17. Last modified 2026-06-17.