Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2016-4861

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.04
EPSS Ranking 87.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
References
Products affected by CVE-2016-4861


Contact Us

Shodan ® - All rights reserved