'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2020-8654: EyesOfNetwork AutoDiscovery Target Command Execution Vulnerability
Severity:high
CVE ID:CVE-2020-8654
| Descripiton:
|
EyesOfNetwork (EON) is an open source, free IT monitoring solution. This solution provides functions such as business process configuration tools and pop-up windows generated when even ts occur in the activity queue. An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module/module_frame/index.php autodiscovery.php target field.This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.