Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Shaojie Jiang

Pesquisador de360 SkyEye Labs
#18607de 53,640
14.4CVSS total
Vulnerabilidades · 2
Alta
2
PT-2017-14353
7.2
2017-10-29
Eyesofnetwork · Eyesofnetwork · CVE-2017-16000
**Name of the Vulnerable Software and Affected Versions** EyesOfNetwork version 5.1-0 **Description** The issue allows remote authenticated administrators to execute arbitrary SQL commands. This is achieved by exploiting the `graph` parameter in the `/module/capacity per label/index.php` API endpoint. **Recommendations** For version 5.1-0, consider restricting access to the `/module/capacity per label/index.php` endpoint until a patch is available, and avoid using the `graph` parameter in this endpoint to minimize the risk of exploitation.
PT-2017-14292
7.2
2017-10-27
Eyesofnetwork · Eyesofnetwork · CVE-2017-15933
**Name of the Vulnerable Software and Affected Versions** EyesOfNetwork version 5.1-0 **Description** The issue allows remote authenticated administrators to execute arbitrary SQL commands. This is achieved by exploiting the `host` parameter in the module/capacity per device/index.php API endpoint. **Recommendations** For version 5.1-0, consider restricting access to the `module/capacity per device/index.php` endpoint until a patch is available. As a temporary workaround, avoid using the `host` parameter in this endpoint to minimize the risk of exploitation.