CVE-2017-6087: Eonweb Project Eonweb
High severity, CVSS 8.8. EPSS: 7.2% chance of exploitation in the next 30 days.
EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] parameter in the (1) acknowledge, (2) delete, or (3) ownDisown function in module/monitoring_ged/ged_functions.php or the (4) module parameter to module/index.php.
Affected products
- Eonweb Project Eonweb: up to and including 5.0-0
Published 2017-03-24. Last modified 2026-06-17.