CVE-2020-8656
critical · 9.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.
9.8
CVSS
84.6%
EPSS (exploit prob.)
100th
EPSS percentile
2020-02-07
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| eyesofnetwork | eyesofnetwork | 5.3-0 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/156266/EyesOfNetwork-5.3-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/156605/EyesOfNetwork-AutoDiscovery-Target-Command-Execution.html
- https://github.com/EyesOfNetworkCommunity/eonapi/issues/16
- http://packetstormsecurity.com/files/156266/EyesOfNetwork-5.3-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/156605/EyesOfNetwork-AutoDiscovery-Target-Command-Execution.html
- https://github.com/EyesOfNetworkCommunity/eonapi/issues/16
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-8656