Known Vulnerabilities for products from Eyesofnetwork

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Eyesofnetwork".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2022-41571 json An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur. 9.8 - CRITICAL 2022-09-27 2022-09-28
CVE-2022-41570 json An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur. 9.8 - CRITICAL 2022-09-27 2022-09-28
CVE-2022-41434 json EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the compo... 6.1 - MEDIUM 2022-11-08 2022-11-08
CVE-2022-41433 json EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the compo... 4.8 - MEDIUM 2022-11-08 2022-11-08
CVE-2022-41432 json EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the compo... 4.8 - MEDIUM 2022-11-08 2022-11-08
CVE-2022-24612 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 5.4 - MEDIUM 2022-02-25 2022-03-04
CVE-2021-40643 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 9.8 - CRITICAL 2022-06-30 2022-07-11
CVE-2021-33525 json EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in the ... 8.8 - HIGH 2021-05-24 2021-05-27
CVE-2021-27514 json EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force ... 9.8 - CRITICAL 2021-02-22 2021-02-26
CVE-2021-27513 json The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it... 8.8 - HIGH 2021-02-22 2021-02-26
CVE-2020-27887 json An issue was discovered in EyesOfNetwork 5.3 through 5.3-8. An authenticated web user with sufficient privileges could abuse ... 8.8 - HIGH 2020-10-29 2021-02-23
CVE-2020-27886 json An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injection, al... 9.8 - CRITICAL 2020-10-29 2021-02-23
CVE-2020-24390 json eonweb in EyesOfNetwork before 5.3-7 does not properly escape the username on the /module/admin_logs page, which might allow ... 6.1 - MEDIUM 2020-08-27 2020-09-02
CVE-2020-9465 json An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL inje... 9.8 - CRITICAL 2020-02-28 2021-02-23
CVE-2020-8657 json An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_... 9.8 - CRITICAL 2020-02-06 2022-01-01
CVE-2020-8656 json An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthentica... 9.8 - CRITICAL 2020-02-07 2022-01-01
CVE-2020-8655 json An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, all... 7.8 - HIGH 2020-02-07 2022-01-01
CVE-2020-8654 json An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscov... 8.8 - HIGH 2020-02-07 2021-12-30
CVE-2019-14923 json EyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field. 8.8 - HIGH 2019-08-16 2021-02-23
CVE-2017-1000060 json EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root Not Provided 2017-07-17 2025-04-20

Known software with vulnerabilities from Eyesofnetwork

Type Vendor Product Version
ApplicationEyesofnetworkEonweb4.2-3
ApplicationEyesofnetworkEyesofnetwork4.2-3