4.3
CVSSv2

CVE-2013-0141

Published: 01/05/2013 Updated: 16/11/2017
CVSS v2 Base Score: 4.3 | Impact Score: 4.9 | Exploitability Score: 5.5
VMScore: 383
Vector: AV:A/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 4.5.7 and 4.6.x prior to 4.6.6 allows remote malicious users to upload arbitrary files via a crafted request over the Agent-Server communication channel, as demonstrated by writing to the Software/ directory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mcafee epolicy orchestrator 3.6.0

mcafee epolicy orchestrator 3.5.0

mcafee epolicy orchestrator 4.5.5

mcafee epolicy orchestrator 4.5.4

mcafee epolicy orchestrator 4.0

mcafee epolicy orchestrator 3.6.1

mcafee epolicy orchestrator 2.5

mcafee epolicy orchestrator 2.0

mcafee epolicy orchestrator 4.5.0

mcafee epolicy orchestrator 2.5.1

mcafee epolicy orchestrator 3.0

mcafee epolicy orchestrator 4.5.3

mcafee epolicy orchestrator

mcafee epolicy orchestrator 4.6.4

mcafee epolicy orchestrator 4.6.3

mcafee epolicy orchestrator 4.6.1

mcafee epolicy orchestrator 4.6.5

mcafee epolicy orchestrator 4.6.0

mcafee epolicy orchestrator 4.6.2

Github Repositories

McAfee ePolicy 0wner exploit code

INTRODUCTION This is "ePolicy 0wner", a sexy exploit aginst McAfee ePolicy Orchestrator versions 460 -> 465 Author: jeromenokin@gmailcom Blog: funoveripnet Discovered on: 20 November 2012 Fixed on: 25 April 2013 In short, this tool registers a rogue agent on the ePo server and then takes advantage of the following vulnerabilities to perfo