Sploitus

CVE-2016-4861

No indexed exploits for CVE-2016-4861 yet

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.

Affected products
Zend Framework
Fedoraproject Fedora
= 23, 24, 25
Fix
Available
CVSS 3.0
9.8 CRITICAL
EPSS
4.1% (90th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2017-02-16
CVE-2016-4861 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2016-4861 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2016-4861 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.