Show filters
39 Total Results
Displaying 1-10 of 39
Sort by:
Attacker Value
Unknown

CVE-2020-9465

Disclosure Date: February 28, 2020 (last updated February 21, 2025)
An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the user_id field in a cookie.
Attacker Value
Unknown

CVE-2022-41432

Disclosure Date: November 08, 2022 (last updated December 22, 2024)
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/report_event/index.php.
Attacker Value
Unknown

CVE-2022-41434

Disclosure Date: November 08, 2022 (last updated December 22, 2024)
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /lilac/main.php.
Attacker Value
Unknown

CVE-2022-41433

Disclosure Date: November 08, 2022 (last updated December 22, 2024)
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/admin_bp/add_application.php.
Attacker Value
Unknown

CVE-2022-41571

Disclosure Date: September 27, 2022 (last updated October 08, 2023)
An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur.
Attacker Value
Unknown

CVE-2022-41570

Disclosure Date: September 27, 2022 (last updated October 08, 2023)
An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.
Attacker Value
Unknown

CVE-2021-40643

Disclosure Date: June 30, 2022 (last updated October 07, 2023)
EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the location of the "sendmail" application in the "cacti" configuration page (by default/usr/sbin/sendmail) it is possible to execute any command, which will be executed when we make a test of the configuration ("send test mail").
Attacker Value
Unknown

CVE-2022-24612

Disclosure Date: February 25, 2022 (last updated October 07, 2023)
An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in a stored XSS.
Attacker Value
Unknown

CVE-2021-33525

Disclosure Date: May 24, 2021 (last updated February 22, 2025)
EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in the nagios_path parameter to lilac/export.php, as demonstrated by %26%26+curl to insert an "&& curl" substring for the shell.
Attacker Value
Unknown

CVE-2021-27514

Disclosure Date: February 22, 2021 (last updated February 22, 2025)
EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).