CVE-2014-2588

McAfee Asset Manager 6.6 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-2588. PoCs published by Brandon Perry.

AI-analyzed exploit summary The document describes multiple vulnerabilities in McAfee Asset Manager v6.6, including an authenticated arbitrary file read via directory traversal and an authenticated SQL injection via the 'user' parameter in the audit report functionality. It provides technical details and example HTTP requests for exploitation.

Description

Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the reportFileName parameter.

Exploits (1)

exploitdb WRITEUP
by Brandon Perry · textwebappsjsp
https://www.exploit-db.com/exploits/32368

The document describes multiple vulnerabilities in McAfee Asset Manager v6.6, including an authenticated arbitrary file read via directory traversal and an authenticated SQL injection via the 'user' parameter in the audit report functionality. It provides technical details and example HTTP requests for exploitation.

Classification
Writeup 90%
Attack Type
Sqli | Info Leak
Complexity
Moderate
Reliability
Reliable
Target: McAfee Asset Manager v6.6
Auth required
Prerequisites: Authenticated access to the McAfee Asset Manager web interface
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/104633
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/66302
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1029927
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Mar/325
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/32368
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/91930

Scores

EPSS 0.0732
EPSS Percentile 93.6%

Details

CWE
CWE-22
Status published
Products (1)
mcafee/asset_manager 6.6
Published Mar 24, 2014
Tracked Since Feb 18, 2026