CVE-2020-8656 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 84.6% (pctl 100)
Patch early
A public exploit exists.
Description
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 84.6% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-02-07 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| eyesofnetwork | eyesofnetwork |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit) | 2020-03-05 |
| exploit-db | EyesOfNetwork 5.3 - Remote Code Execution | 2020-02-07 |
References
- http://packetstormsecurity.com/files/156266/EyesOfNetwork-5.3-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/156605/EyesOfNetwork-AutoDiscovery-Target-Command-Execution.html
- https://github.com/EyesOfNetworkCommunity/eonapi/issues/16
- http://packetstormsecurity.com/files/156266/EyesOfNetwork-5.3-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/156605/EyesOfNetwork-AutoDiscovery-Target-Command-Execution.html
- https://github.com/EyesOfNetworkCommunity/eonapi/issues/16
→ the Explorer · watch your stack · NVD