Critical severity9.8NVD Advisory· Published Dec 29, 2017· Updated Jun 17, 2026
CVE-2014-4914
CVE-2014-4914
Description
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
6- framework.zend.com/security/advisory/ZF2014-04nvdVendor Advisory
- jvn.jp/en/jp/JVN71730320/index.htmlnvdThird Party AdvisoryVDB Entry
- openwall.com/lists/oss-security/2014/07/11/4nvdMailing ListThird Party Advisory
- secunia.com/advisories/58847nvdThird Party Advisory
- www.securityfocus.com/bid/68031nvdThird Party AdvisoryVDB Entry
- www.debian.org/security/2015/dsa-3265nvdThird Party Advisory
News mentions
0No linked articles in our index yet.