CVE-2021-33525 Information
Jun 07, 2022
cve
Description
EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in the nagios_path parameter to lilac/export.php as demonstrated by %26%26+curl to insert an && curl\ substring for the shell.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/EyesOfNetworkCommunity/eonweb/releases
https://github.com/ArianeBlow/LilacPathVUln/blob/main/eon-pwn.sh
EyesOfNetwork
eonweb
through
5.3-11
allows
Remote
Command
Execution
(by
authenticated
users)
via
shell
metacharacters
in
the
nagios_path
parameter
to
lilac/export.php
as
demonstrated
by
%26%26+curl
to
insert
an
&&
curl
substring
for
the
shell.
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: