Hack the Elephant One Bite at a Time: NUL byte SQL Injection in pdo_firebird and NULL Pointer Dereference in PDO via pdo_pgsql
swarm.ptsecurity.com | research | #vulnerability-research | #memory-safety | #denial-of-service | #php | #sql-injection | #pdo | #firebird | #cve-2025-14179 | #cve-2025-14180
Summary
Positive Technologies details two PHP PDO flaws: CVE-2025-14179, SQL injection in pdo_firebird via NUL bytes in quoted strings, and CVE-2025-14180, a NULL pointer dereference in PDO quoting.
- Published
- Collected
Skip to content