7.2
CVSSv3

CVE-2017-6088

Published: 11/04/2017 Updated: 13/03/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and previous versions allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) display, (3) search, or (4) equipment parameter to module/monitoring_ged/ged_functions.php or the (5) type parameter to monitoring_ged/ajax.php.

Vulnerable Product Search on Vulmon Subscribe to Product

eyesofnetwork eyesofnetwork

Exploits

# [CVE-2017-6088] EON 50 Multiple SQL Injection ## Description EyesOfNetwork ("EON") is an OpenSource network monitoring solution ## SQL injection (authenticated) The Eonweb code does not correctly filter arguments, allowing authenticated users to inject arbitrary SQL requests **CVE ID**: CVE-2017-6088 **Access Vector**: remote **Security ...
EON versions 50 and below suffer from a remote SQL injection vulnerability ...