vendor:
EyesOfNetwork
by:
Dany Bach
9,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: EyesOfNetwork
Affected Version From: EyesOfNetwork 5.0
Affected Version To: EyesOfNetwork 5.1
Patch Exists: NO
Related CWE: None
CPE: a:eyesofnetwork:eyesofnetwork
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: EyesOfNetwork 5.1 and 5.0
2017
EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root
This exploit is an unauthenticated SQL injection in EyesOfNetwork 5.1, which allows an attacker to gain remote root access. The exploit is based on a DELETE statement, which is used to delete all entries in the [sessions] table except one. The session_id is then retrieved by using a combination of SLEEP and SUBSTR functions.
Mitigation:
None