EyesOfNetwork(EON)是一套开源的、免费的IT监控解决方案。该方案提供业务流程配置工具、在活动队列中发生事件时生成弹出窗口等功能。 EyesOfNetwork 5.3版本中的AutoDiscovery模块存在操作系统命令注入漏洞。攻击者可借助‘target’参数利用该漏洞运行任意操作系统命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | EyesOfNetwork 5.1 to 5.3 contains SQL injection and remote code execution vulnerabilities. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site. See also CVE-2020-8655, CVE-2020-8656, CVE-2020-8657, and CVE-2020-9465. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-8654.yaml | POC Details |
| CVE-2020-6760 | Schmid ZI 操作系统命令注入漏洞 | |
| CVE-2020-5720 | MikroTik WinBox 路径遍历漏洞 | |
| CVE-2020-7920 | Percona Monitoring and Management 资源管理错误漏洞 | |
| CVE-2012-6297 | DD-WRT 24-sp2 跨站请求伪造漏洞 | |
| CVE-2012-6306 | HCView 安全漏洞 | |
| CVE-2012-6307 | JPEGsnoop 安全漏洞 | |
| CVE-2012-6309 | Arctic Torrent 安全漏洞 | |
| CVE-2020-8657 | EyesOfNetwork 信任管理问题漏洞 | |
| CVE-2012-6340 | NETGEAR WGR614 授权问题漏洞 | |
| CVE-2012-6341 | NEtGEAR WGR614 信息泄露漏洞 | |
| CVE-2020-8636 | OpServices OpMon 访问控制错误漏洞 | |
| CVE-2013-2683 | Cisco Linksys E4200 信息泄露漏洞 | |
| CVE-2013-2684 | Cisco Linksys E4200 跨站脚本漏洞 | |
| CVE-2013-3564 | VideoLAN VLC media player 信息泄露漏洞 | |
| CVE-2013-3568 | Cisco Linksys WRT110 跨站请求伪造漏洞 | |
| CVE-2013-3638 | Boonex Dolphin SQL注入漏洞 | |
| CVE-2020-8656 | EyesOfNetwork SQL注入漏洞 | |
| CVE-2020-8645 | Simplejobscript SQL注入漏洞 | |
| CVE-2020-8655 | EyesOfNetwork 安全漏洞 | |
| CVE-2019-10789 | curling 操作系统命令注入漏洞 |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet