CVE-2020-8656
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.
- Affected products
- Eyesofnetwork, Eyesofnetwork Api
- Eyesofnetwork
- = 5.3-0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 84.6% (100th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2020-02-06
CVE-2020-8656 at NVD
8 known exploits for CVE-2020-8656
Proof-of-concept code and exploit modules indexed by Sploitus
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
EyesOfNetwork AutoDiscovery Target Command Execution Exploit
EyesOfNetwork AutoDiscovery Target Command Execution
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
EyesOfNetwork 5.3 Remote Code Execution
EyesOfNetwork 5.3 Remote Code Execution Exploit
EyesOfNetwork 5.3 - Remote Code Execution
EyesOfNetwork 5.3 - Remote Code Execution