vendor:
EyesOfNetwork
by:
Audencia Business SCHOOL Red Team
8.8
CVSS
HIGH
Local File Inclusion (LFI)
98
CWE
Product Name: EyesOfNetwork
Affected Version From: 5.3
Affected Version To: 5.3
Patch Exists: NO
Related CWE: N/A
CPE: a:eyesofnetwork:eyesofnetwork:5.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2021
EyesOfNetwork 5.3 – LFI
The php not exclude other tools than proposed one. It's possible possible to include files when the parameter 'tool_list=' is modified. By modifying the parameter, it is possible to print the /etc/passwd document in the webpage.
Mitigation:
Ensure that user input is properly validated and sanitized to prevent malicious code from being executed.