Vulnerability Description
EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in the nagios_path parameter to lilac/export.php, as demonstrated by %26%26+curl to insert an "&& curl" substring for the shell.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eyesofnetwork | Eyesofnetwork | <= 5.3-11 |
Related Weaknesses (CWE)
References
- https://github.com/ArianeBlow/LilacPathVUln/blob/main/eon-pwn.shExploitThird Party Advisory
- https://github.com/EyesOfNetworkCommunity/eonweb/releasesRelease NotesThird Party Advisory
- https://github.com/ArianeBlow/LilacPathVUln/blob/main/eon-pwn.shExploitThird Party Advisory
- https://github.com/EyesOfNetworkCommunity/eonweb/releasesRelease NotesThird Party Advisory
FAQ
What is CVE-2021-33525?
CVE-2021-33525 is a vulnerability with a CVSS score of 8.8 (HIGH). EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in the nagios_path parameter to lilac/export.php, as demonstrated by %26%26+curl t...
How severe is CVE-2021-33525?
CVE-2021-33525 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-33525?
Check the references section above for vendor advisories and patch information. Affected products include: Eyesofnetwork Eyesofnetwork.