### [CVE-2016-4861](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4861) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation. ### POC #### Reference No PoCs from references. #### Github - https://github.com/KosukeShimofuji/CVE-2016-4861