Show filters
39 Total Results
Displaying 31-39 of 39
Sort by:
Attacker Value
Unknown

CVE-2017-14401

Disclosure Date: September 13, 2017 (last updated November 26, 2024)
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT UPDATE" section.
0
Attacker Value
Unknown

CVE-2017-14405

Disclosure Date: September 13, 2017 (last updated November 26, 2024)
The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote command execution via shell metacharacters in a hosts_cacti array parameter to module/admin_device/index.php.
0
Attacker Value
Unknown

CVE-2017-14252

Disclosure Date: September 11, 2017 (last updated November 26, 2024)
SQL Injection exists in the EyesOfNetwork web interface (aka eonweb) 5.1-0 via the group_id cookie to side.php.
0
Attacker Value
Unknown

CVE-2017-14247

Disclosure Date: September 11, 2017 (last updated November 26, 2024)
SQL Injection exists in the EyesOfNetwork web interface (aka eonweb) 5.1-0 via the user_id cookie to header.php, a related issue to CVE-2017-1000060.
0
Attacker Value
Unknown

CVE-2017-14118

Disclosure Date: September 03, 2017 (last updated November 26, 2024)
In the EyesOfNetwork web interface (aka eonweb) 5.1-0, module\tool_all\tools\interface.php does not properly restrict exec calls, which allows remote attackers to execute arbitrary commands via shell metacharacters in the host_list parameter to module/tool_all/select_tool.php.
0
Attacker Value
Unknown

CVE-2017-14119

Disclosure Date: September 03, 2017 (last updated November 26, 2024)
In the EyesOfNetwork web interface (aka eonweb) 5.1-0, module\tool_all\tools\snmpwalk.php does not properly restrict popen calls, which allows remote attackers to execute arbitrary commands via shell metacharacters in a parameter.
0
Attacker Value
Unknown

CVE-2017-13780

Disclosure Date: August 30, 2017 (last updated November 26, 2024)
The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows directory traversal attacks for reading arbitrary files via the module/admin_conf/download.php file parameter.
0
Attacker Value
Unknown

CVE-2017-1000060

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root
Attacker Value
Unknown

CVE-2017-6088

Disclosure Date: April 11, 2017 (last updated November 26, 2024)
Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) display, (3) search, or (4) equipment parameter to module/monitoring_ged/ged_functions.php or the (5) type parameter to monitoring_ged/ajax.php.
0