CVE-2011-1939
SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.
- Affected products
- Pdo Mysql, Php, Zend Framework
- Zend Zend Framework
- < 1.10.9, 1.11.6
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 3.9% (89th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2019-11-26
CVE-2011-1939 at NVD
1 known exploit for CVE-2011-1939
Proof-of-concept code and exploit modules indexed by Sploitus