SQL Injection exists in the EyesOfNetwork web interface (aka eonweb) 5.1-0 via the user_id cookie to header.php, a related issue to CVE-2017-1000060.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores