Show filters
52 Total Results
Displaying 1-10 of 52
Sort by:
Attacker Value
Unknown
CVE-2020-9465
Disclosure Date: February 28, 2020 (last updated February 21, 2025)
An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the user_id field in a cookie.
1
Attacker Value
Unknown
CVE-2020-27633
Disclosure Date: October 10, 2023 (last updated October 14, 2023)
In FNET 4.6.3, TCP ISNs are improperly random.
0
Attacker Value
Unknown
CVE-2022-41571
Disclosure Date: September 27, 2022 (last updated October 08, 2023)
An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur.
0
Attacker Value
Unknown
CVE-2022-41570
Disclosure Date: September 27, 2022 (last updated October 08, 2023)
An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.
0
Attacker Value
Unknown
CVE-2021-40643
Disclosure Date: June 30, 2022 (last updated October 07, 2023)
EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the location of the "sendmail" application in the "cacti" configuration page (by default/usr/sbin/sendmail) it is possible to execute any command, which will be executed when we make a test of the configuration ("send test mail").
0
Attacker Value
Unknown
CVE-2022-24612
Disclosure Date: February 25, 2022 (last updated October 07, 2023)
An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in a stored XSS.
0
Attacker Value
Unknown
CVE-2021-33525
Disclosure Date: May 24, 2021 (last updated February 22, 2025)
EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in the nagios_path parameter to lilac/export.php, as demonstrated by %26%26+curl to insert an "&& curl" substring for the shell.
0
Attacker Value
Unknown
CVE-2021-27514
Disclosure Date: February 22, 2021 (last updated February 22, 2025)
EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).
0
Attacker Value
Unknown
CVE-2021-27513
Disclosure Date: February 22, 2021 (last updated February 22, 2025)
The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."
0
Attacker Value
Unknown
CVE-2020-17470
Disclosure Date: December 11, 2020 (last updated February 22, 2025)
An issue was discovered in FNET through 4.6.4. The code that initializes the DNS client interface structure does not set sufficiently random transaction IDs (they are always set to 1 in _fnet_dns_poll in fnet_dns.c). This significantly simplifies DNS cache poisoning attacks.
0