Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Shaojie Jiang

Researcher from360 SkyEye Labs
#18638of 53,638
14.4Total CVSS
Vulnerabilities · 2
High
2
PT-2017-14353
7.2
2017-10-29
Eyesofnetwork · Eyesofnetwork · CVE-2017-16000
**Name of the Vulnerable Software and Affected Versions** EyesOfNetwork version 5.1-0 **Description** The issue allows remote authenticated administrators to execute arbitrary SQL commands. This is achieved by exploiting the `graph` parameter in the `/module/capacity per label/index.php` API endpoint. **Recommendations** For version 5.1-0, consider restricting access to the `/module/capacity per label/index.php` endpoint until a patch is available, and avoid using the `graph` parameter in this endpoint to minimize the risk of exploitation.
PT-2017-14292
7.2
2017-10-27
Eyesofnetwork · Eyesofnetwork · CVE-2017-15933
**Name of the Vulnerable Software and Affected Versions** EyesOfNetwork version 5.1-0 **Description** The issue allows remote authenticated administrators to execute arbitrary SQL commands. This is achieved by exploiting the `host` parameter in the module/capacity per device/index.php API endpoint. **Recommendations** For version 5.1-0, consider restricting access to the `module/capacity per device/index.php` endpoint until a patch is available. As a temporary workaround, avoid using the `host` parameter in this endpoint to minimize the risk of exploitation.