14 exploited vulnerabilities in Zend Framework
- Vendors
- Laminas, Zend, Php, Piwik, Smarty, Suse
- With known exploits
- 14
- Affected Getlaminas Laminas-http versions
- < 2.14.2
- Affected Zend Zend Framework versions
- = 3.0.0, 2.4.10, 1.11.12, 1.12.0, 1.10.9, 1.11.6, 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.5.0, 1.5.1, 1.5.2, 1.5.3, 1.6.0, 1.6.1, 1.6.2, 1.7.0, 1.7.1, 1.7.2, 1.7.3, 1.7.4, 1.7.5, 1.7.6, 1.7.7, 1.7.8, 1.7.9, 1.8.0, 1.8.1, 1.8.2, 1.8.3, 1.8.4, 1.8.5, 1.9.0, 1.9.1, 1.9.2, 1.9.3, 1.9.4, 1.9.5, 1.9.6, 1.9.7, 1.9.8, 1.10.0, 1.10.1, 1.10.2
- Affected Matomo versions
- = 0.2.25, 0.2.26, 0.2.27, 0.2.28, 0.2.29, 0.2.30, 0.2.31, 0.2.32
Vulnerabilities with exploits
Highest CVSS first — 6 of these already have exploit code on Sploitus
CVE-2021-3007 2 exploits
Exploit for Deserialization of Untrusted Data in Getlaminas Laminas-HttpExploit for Deserialization of Untrusted Data in Getlaminas Laminas-Http
CVE-2014-8089
CVE-2015-0270
CVE-2016-6233
CVE-2016-4861
CVE-2016-10034 9 exploits
PHPMailer < 5.2.20 with Exim MTA - Remote Code Execution ExploitPHPMailer 5.2.20 with Exim MTA - Remote Code Execution
CVE-2012-3363 2 exploits
DSquare Exploit Pack: D2SEC_ZEND_XMLRPCZend Framework < 2.0.0 beta4 < 1.12 RC1 < 1.11.11 - Local File Disclosure
CVE-2015-1786
CVE-2011-1939 1 exploit
CVE-2015-7503
CVE-2009-4137 2 exploits
CVE-2015-5161 6 exploits
eBay Magento 1.9.2.1 - PHP FPM XML eXternal Entity InjectioneBay Magento 1.9.2.1 - PHP FPM XML eXternal Entity Injection
CVE-2015-3154
CVE-2009-4417