Executive brief
EyesOfNetwork 5.3 contains an improper privilege management vulnerability in its sudoers configuration. An attacker with apache user privileges can escalate to root by executing arbitrary commands via a crafted Nmap Scripting Engine (NSE) script using nmap7.
Affected products
- EyesOfNetwork EyesOfNetwork 5.3
Timeline
- 2020-02-06: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog