← Back

CVE-2013-4882

nvd nist
Published: Jul 22, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (ePO) extension for McAfee Agent (MA) 4.5 and 4.6, allow remote authenticated users to execute arbitrary SQL commands via the uid parameter to (1) core/showRegisteredTypeDetails.do and (2) EPOAGENTMETA/DisplayMSAPropsDetail.do, a different vulnerability than CVE-2013-0140.

Affected (9)

2 products
Epolicy Orchestrator
Epolicy Orchestrator Agent
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Mcafee
Up to 4.6.6
Version 4.6.0
Version 4.6.1
Version 4.6.2
Version 4.6.3
Version 4.6.4
Version 4.6.5
Mcafee
Version 4.5
Version 4.6

References (6)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.