Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Hack the Elephant One Bite at a Time: NUL byte SQL Injection in pdo_firebird and NULL Pointer Dereference in PDO via pdo_pgsql

Summary

Positive Technologies details two PHP PDO flaws: CVE-2025-14179, SQL injection in pdo_firebird via NUL bytes in quoted strings, and CVE-2025-14180, a NULL pointer dereference in PDO quoting.
Published
Collected

original ↗

Related coverage

back