{"api_version":"1","generated_at":"2026-07-23T03:23:48+00:00","cve":"CVE-2016-8341","urls":{"html":"https://cve.report/CVE-2016-8341","api":"https://cve.report/api/cve/CVE-2016-8341.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-8341","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-8341"},"summary":{"title":"CVE-2016-8341","description":"An issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized, the host's database could be subject to read, write, and delete commands.","state":"PUBLISHED","assigner":"icscert","published_at":"2017-02-13 21:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-89","Ecava IntegraXor SQL injection"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/95907","name":"http://www.securityfocus.com/bid/95907","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Ecava IntegraXor CVE-2016-8341 Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-031-02","name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-031-02","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Third Party Advisory","US Government Resource"],"title":"Ecava IntegraXor | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-8341","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-8341","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"Ecava IntegraXor 5.0.413.0","version":"affected Ecava IntegraXor 5.0.413.0","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"8341","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"5.0.413.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T02:20:30.621Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"95907","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/95907"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-031-02"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Ecava IntegraXor 5.0.413.0","vendor":"n/a","versions":[{"status":"affected","version":"Ecava IntegraXor 5.0.413.0"}]}],"datePublic":"2017-02-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"An issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized, the host's database could be subject to read, write, and delete commands."}],"problemTypes":[{"descriptions":[{"description":"Ecava IntegraXor SQL injection","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-02-14T10:57:01.000Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"name":"95907","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/95907"},{"tags":["x_refsource_MISC"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-031-02"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2016-8341","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Ecava IntegraXor 5.0.413.0","version":{"version_data":[{"version_value":"Ecava IntegraXor 5.0.413.0"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized, the host's database could be subject to read, write, and delete commands."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Ecava IntegraXor SQL injection"}]}]},"references":{"reference_data":[{"name":"95907","refsource":"BID","url":"http://www.securityfocus.com/bid/95907"},{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-031-02","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-031-02"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2016-8341","datePublished":"2017-02-13T21:00:00.000Z","dateReserved":"2016-09-28T00:00:00.000Z","dateUpdated":"2024-08-06T02:20:30.621Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-02-13 21:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-89","Ecava IntegraXor SQL injection"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:5.0.413.0:*:*:*:*:*:*:*","matchCriteriaId":"C1799D06-1DD1-4565-B1A0-6504D705D475"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"8341","Ordinal":"1","Title":"CVE-2016-8341","CVE":"CVE-2016-8341","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"8341","Ordinal":"1","NoteData":"An issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized, the host's database could be subject to read, write, and delete commands.","Type":"Description","Title":"CVE-2016-8341"},{"CveYear":"2016","CveId":"8341","Ordinal":"2","NoteData":"2017-02-13","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"8341","Ordinal":"3","NoteData":"2017-02-14","Type":"Other","Title":"Modified"}]}}}