CVE-2016-2299 describes a SQL injection vulnerability in Ecava IntegraXor versions prior to 5.0 build 4522, allowing remote attackers to execute arbitrary SQL commands through unspecified vectors. This vulnerability carries a CVSS v3 score of 7.3 (HIGH), indicating a network-based attack with low complexity and potential for limited impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, including an article from SecurityWeek. Its EPSS score is low, suggesting a minimal likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.2.4502CPE matchmatch criteria | cpe:2.3:a:ecava:integraxor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.