CVE-2013-4882

McAfee ePolicy Orchestrator <4.6.6 - SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (ePO) extension for McAfee Agent (MA) 4.5 and 4.6, allow remote authenticated users to execute arbitrary SQL commands via the uid parameter to (1) core/showRegisteredTypeDetails.do and (2) EPOAGENTMETA/DisplayMSAPropsDetail.do, a different vulnerability than CVE-2013-0140.

Exploits (1)

exploitdb WRITEUP
webappswindows
https://www.exploit-db.com/exploits/26807

Scores

EPSS 0.0110
EPSS Percentile 78.1%

Details

CWE
CWE-89
Status published
Products (9)
mcafee/epolicy_orchestrator 4.6.0
mcafee/epolicy_orchestrator 4.6.1
mcafee/epolicy_orchestrator 4.6.2
mcafee/epolicy_orchestrator 4.6.3
mcafee/epolicy_orchestrator 4.6.4
mcafee/epolicy_orchestrator 4.6.5
mcafee/epolicy_orchestrator < 4.6.6
mcafee/epolicy_orchestrator_agent 4.5
mcafee/epolicy_orchestrator_agent 4.6
Published Jul 22, 2013
Tracked Since Feb 18, 2026