6.5
CVSSv2

CVE-2014-2587

Published: 24/03/2014 Updated: 29/08/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated users to execute arbitrary SQL commands via the username of an audit report (aka user parameter).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mcafee asset manager 6.6

Exploits

Cloud SSO is vuln to unauthed XSS in the authentication audit form: twittercom/BrandonPrry/status/445969380656943104 McAfee Asset Manager v66 multiple vulnerabilities wwwmcafeecom/us/products/asset-manageraspx Authenticated arbitrary file read An unprivileged authenticated user can download arbitrary files with the permissio ...