peter bassill · operator
$ cve CVE-2017-6087 JSON

CVE-2017-6087 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 7.2% (pctl 94)

Patch early

A public exploit exists.

Description

EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] parameter in the (1) acknowledge, (2) delete, or (3) ownDisown function in module/monitoring_ged/ged_functions.php or the (4) module parameter to module/index.php.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS7.18% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2017-03-24
Last modified2026-06-17

Affected (1)

VendorProduct
eonweb projecteonweb

Public exploits

SourceTitleDate
exploit-dbEyesOfNetwork (EON) 5.0 - Remote Code Execution2017-03-27

References

→ the Explorer  ·  watch your stack  ·  NVD