vendor:
EyesOfNetwork 5.3
by:
Ariane.Blow
9.8
CVSS
HIGH
Remote Code Execution
434
CWE
Product Name: EyesOfNetwork 5.3
Affected Version From: 5.3
Affected Version To: 5.3-10
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2021
EyesOfNetwork 5.3 – File Upload Remote Code Execution
EyesOfNetwork 5.3 is vulnerable to a remote code execution vulnerability due to an arbitrary file upload. An attacker can exploit this vulnerability by uploading a malicious file to the server and then executing it. This can be done by using the curl command to upload the file and then using the curl command to execute it. The attacker can then start a listener on their machine to receive the output of the malicious file.
Mitigation:
The best way to mitigate this vulnerability is to ensure that all user input is properly validated and sanitized before being used. Additionally, it is important to ensure that all files uploaded to the server are scanned for malicious content.