CVE-2020-8656
Summary
| CVE | CVE-2020-8656 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-07 00:15:00 UTC |
| Updated | 2022-01-01 19:57:00 UTC |
| Description | An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Injection SQL sur le champ username de getApiKey · Issue #16 · EyesOfNetworkCommunity/eonapi · GitHub |
MISC |
github.com |
Third Party Advisory |
| EyesOfNetwork AutoDiscovery Target Command Execution ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| EyesOfNetwork 5.3 Remote Code Execution ≈ Packet Storm |
MISC |
packetstormsecurity.com |
Exploit, Third Party Advisory, VDB Entry |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730386 EyesOfNetwork Multiple Vulnerabilities