Vulnerability Details CVE-2017-6088
Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) display, (3) search, or (4) equipment parameter to module/monitoring_ged/ged_functions.php or the (5) type parameter to monitoring_ged/ajax.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.069
EPSS Ranking 90.9%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 9.0
Products affected by CVE-2017-6088
-
cpe:2.3:a:eyesofnetwork:eyesofnetwork:4.2-3
-
cpe:2.3:a:eyesofnetwork:eyesofnetwork:4.3-0
-
cpe:2.3:a:eyesofnetwork:eyesofnetwork:5.0