CVE-2016-3694

CRITICAL ⚠ Exploit

Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remote attackers to execute arbitrary SQL commands ...

Affects 1 product across 1 vendor.

BCS8.46
CVSS 3.09.8
EPSS3.1%
Percentile87th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-89: SQL Injection

Attacker inserts SQL commands into application queries through user-controlled input, allowing unauthorized database access.

Related Attack Patterns (CAPEC)
CAPEC-7 Blind SQL Injection
via CWE-89
CAPEC-108 Command Line Execution through SQL Injection
via CWE-89
CAPEC-109 Object Relational Mapping Injection
via CWE-89
CAPEC-110 SQL Injection through SOAP Parameter Tampering
via CWE-89
CAPEC-470 Expanding Control over the Operating System from the Database
via CWE-89
Show all 6
via CWE-89

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, specifically in the easybill-module, allow remote attackers to execute arbitrary SQL commands through the orders_status or customers_status parameters in api/easybill/easybillcsv.php.

BSID: BS-2017-GLOBAL-165571-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2016-3694?
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, specifically in the easybill-module, allow remote attackers to execute arbitrary SQL commands through the orders_status or customers_status parameters in api/easybill/easybillcsv.php.
What is the CVSS score for CVE-2016-3694?
CVE-2016-3694 has CVSS 9.8 (Critical). Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 3.1%.
Is CVE-2016-3694 actively exploited?
Public exploit available for CVE-2016-3694. Exploitation risk elevated.
How do I remediate CVE-2016-3694?
Priority: IMMEDIATE.
What systems are affected by CVE-2016-3694?
CVE-2016-3694 affects: Modified.
Vulnerability Details
CVE IDCVE-2016-3694
BSIDBS-2017-GLOBAL-165571-C BreachSpider Global ID
CVSS VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2017-02-15
Last Modified2026-05-13
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remote attackers to execute arbitrary SQL commands via the (1) orders_status or (2) customers_status parameter to api/easybill/easybillcsv.php.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerabilities are due to improper input validation in the easybill-module of the modified eCommerce Shopsoftware. Attackers can exploit these vulnerabilities by sending specially crafted requests to the api/easybill/easybillcsv.php endpoint with malicious SQL code in the orders_status or customers_status parameters.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Modified Ecommerce Shopsoftware
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 3489 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Modified
CVE-1999-0663 10.0 A system-critical program, library, or file has a checksum or other integrity... CVE-2025-4558 9.8 The GPM from WormHole Tech has an Unverified Password Change vulnerability, a... CVE-2026-22903 9.8 An unauthenticated remote attacker can send a crafted HTTP request containing... CVE-2026-42298 9.8 Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn... CVE-2025-5310 9.8 Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented a...
View all Modified CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →