# Public PoC

1 exploit Active since Jul 2017
CVE-2017-11467 METASPLOIT CRITICAL ruby WORKING POC
OrientDB < 2.2.22 - Remote Code Execution via Unprivileged Query Operations
OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbitrary OS commands via a crafted request.
CVSS 9.8