Skip to content

Instantly share code, notes, and snippets.

@delyura
Created September 21, 2022 11:52

Revisions

  1. delyura created this gist Sep 21, 2022.
    44 changes: 44 additions & 0 deletions gistfile1.txt
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,44 @@
    CVE-2022-XXXXX
    ------------------------------------------
    [Suggested description]
    EyesOfNetwork web interface 5.3 allows to conduct reflected XSS attacks.

    ------------------------------------------

    [Vulnerability Type]
    Cross Site Scripting (XSS)

    ------------------------------------------

    [Vendor of Product]
    EyesOfNetwork

    ------------------------------------------

    [Affected Product Code Base]
    EyesOfNetwork web interface 5.3

    ------------------------------------------

    [Affected Component]
    We found reflected xss at /lilac/main.php

    ------------------------------------------

    [Attack Type]
    Remote

    ------------------------------------------

    [Attack Vectors]
    https://github.com/EyesOfNetworkCommunity/eonweb/issues/117

    ------------------------------------------

    [Reference]
    EyesOfNetwork web interface 5.3 (https://github.com/EyesOfNetworkCommunity/eonweb)

    ------------------------------------------

    [Discoverer]
    Yuriy Bairov, Dmitriy Tatarov