Show filters
39 Total Results
Displaying 31-39 of 39
Sort by:
Attacker Value
Unknown
CVE-2017-14401
Disclosure Date: September 13, 2017 (last updated November 26, 2024)
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT UPDATE" section.
0
Attacker Value
Unknown
CVE-2017-14405
Disclosure Date: September 13, 2017 (last updated November 26, 2024)
The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote command execution via shell metacharacters in a hosts_cacti array parameter to module/admin_device/index.php.
0
Attacker Value
Unknown
CVE-2017-14252
Disclosure Date: September 11, 2017 (last updated November 26, 2024)
SQL Injection exists in the EyesOfNetwork web interface (aka eonweb) 5.1-0 via the group_id cookie to side.php.
0
Attacker Value
Unknown
CVE-2017-14247
Disclosure Date: September 11, 2017 (last updated November 26, 2024)
SQL Injection exists in the EyesOfNetwork web interface (aka eonweb) 5.1-0 via the user_id cookie to header.php, a related issue to CVE-2017-1000060.
0
Attacker Value
Unknown
CVE-2017-14118
Disclosure Date: September 03, 2017 (last updated November 26, 2024)
In the EyesOfNetwork web interface (aka eonweb) 5.1-0, module\tool_all\tools\interface.php does not properly restrict exec calls, which allows remote attackers to execute arbitrary commands via shell metacharacters in the host_list parameter to module/tool_all/select_tool.php.
0
Attacker Value
Unknown
CVE-2017-14119
Disclosure Date: September 03, 2017 (last updated November 26, 2024)
In the EyesOfNetwork web interface (aka eonweb) 5.1-0, module\tool_all\tools\snmpwalk.php does not properly restrict popen calls, which allows remote attackers to execute arbitrary commands via shell metacharacters in a parameter.
0
Attacker Value
Unknown
CVE-2017-13780
Disclosure Date: August 30, 2017 (last updated November 26, 2024)
The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows directory traversal attacks for reading arbitrary files via the module/admin_conf/download.php file parameter.
0
Attacker Value
Unknown
CVE-2017-1000060
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root
0
Attacker Value
Unknown
CVE-2017-6088
Disclosure Date: April 11, 2017 (last updated November 26, 2024)
Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) display, (3) search, or (4) equipment parameter to module/monitoring_ged/ged_functions.php or the (5) type parameter to monitoring_ged/ajax.php.
0