### [CVE-2016-2346](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2346) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Allround Automations PL/SQL Developer 11 before 11.0.6 relies on unverified HTTP data for updates, which allows man-in-the-middle attackers to execute arbitrary code by modifying fields in the client-server data stream. ### POC #### Reference - http://www.kb.cert.org/vuls/id/229047 - https://adamcaudill.com/2016/02/02/plsql-developer-nonexistent-encryption/ #### Github No PoCs found on GitHub currently.