EyesOfNetworkCommunity / eonweb

EyesOfNetwork web interface
8 stars 12 forks source link

Security: Unauthenticated sqli, plus lfi allow Remote code execution then, privilege escalation on default installation #120

Open Guilhem7 opened 2 years ago

Guilhem7 commented 2 years ago

As said in the title I found different vulnerabilities in the code that could lead an unauthenticated attacker to take control of the server. For more details about the exploitation scenario you can contact me guilhemrioux@gmail.com