Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2013-0140
Disclosure Date: May 01, 2013 (last updated October 05, 2023)
SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to execute arbitrary SQL commands via a crafted request over the Agent-Server communication channel.
0
Attacker Value
Unknown
CVE-2013-0141
Disclosure Date: May 01, 2013 (last updated October 05, 2023)
Directory traversal vulnerability in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to upload arbitrary files via a crafted request over the Agent-Server communication channel, as demonstrated by writing to the Software/ directory.
0
Attacker Value
Unknown
CVE-2012-4594
Disclosure Date: August 22, 2012 (last updated October 04, 2023)
McAfee ePolicy Orchestrator (ePO) 4.6.1 and earlier allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information from arbitrary reporting panels, via a modified ID value in a console URL.
0
Attacker Value
Unknown
CVE-2008-1357
Disclosure Date: March 17, 2008 (last updated October 04, 2023)
Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used in ePolicy Orchestrator 4.0.0 build 1015, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in a sender field in an AgentWakeup request to UDP port 8082. NOTE: this issue only exists when the debug level is 8.
0
Attacker Value
Unknown
CVE-2006-5156
Disclosure Date: October 05, 2006 (last updated October 04, 2023)
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.
0
Attacker Value
Unknown
CVE-2004-0038
Disclosure Date: June 14, 2004 (last updated February 22, 2025)
McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.
0
Attacker Value
Unknown
CVE-2003-0610
Disclosure Date: August 27, 2003 (last updated February 22, 2025)
Directory traversal vulnerability in ePO agent for McAfee ePolicy Orchestrator 3.0 allows remote attackers to read arbitrary files via a certain HTTP request.
0
Attacker Value
Unknown
CVE-2003-0148
Disclosure Date: August 27, 2003 (last updated February 22, 2025)
The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.
0