VYPR
Critical severity9.8NVD Advisory· Published Nov 26, 2019· Updated Jun 16, 2026

CVE-2011-1939

CVE-2011-1939

Description

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Zend/Framework2 versions
    cpe:2.3:a:zend:zend_framework:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:zend:zend_framework:*:*:*:*:*:*:*:*range: >=1.10.0,<1.10.9
    • (no CPE)range: <1.10.9, <1.11.6
  • PHP/PHP2 versions
    cpe:2.3:a:php:php:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:php:php:*:*:*:*:*:*:*:*range: <5.3.6
    • (no CPE)range: <5.3.6
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • Range: before 5.3.6

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.