The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote command execution via shell metacharacters in a hosts_cacti array parameter to module/admin_device/index.php.
References
Link Resource
http://www.sstrunk.com/cve/eonweb_module_admin_device_index.html Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-09-13T03:00:00

Updated: 2017-09-13T02:57:01

Reserved: 2017-09-12T00:00:00


Link: CVE-2017-14405

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-09-13T03:29:00.370

Modified: 2021-02-23T15:06:16.313


Link: CVE-2017-14405

JSON object: View

cve-icon Redhat Information

No data.

CWE