Description b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php. Remediation References CVE-2016-8901 Related Vulnerabilities Oracle Application Server CVE-2006-5364 Vulnerability (CVE-2006-5364) WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery SQL Injection (1.3.29) Squid Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2009-2621) MySQL CVE-2017-3251 Vulnerability (CVE-2017-3251) MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-5241) Severity Critical Classification CVE-2016-8901 CWE-138 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities