CVE-2013-0140

SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to execute arbitrary SQL commands via a crafted request over the Agent-Server communication channel.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.9 UNKNOWN
ADJACENT_NETWORK
MEDIUM
AV:A/AC:M/Au:N/C:C/I:C/A:C
certccCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
mcafeeepolicy_orchestrator
𝑥
≤ 4.5.6
mcafeeepolicy_orchestrator
2.0
mcafeeepolicy_orchestrator
2.5
mcafeeepolicy_orchestrator
2.5:sp1
mcafeeepolicy_orchestrator
2.5.1
mcafeeepolicy_orchestrator
3.0
mcafeeepolicy_orchestrator
3.0:sp2a
mcafeeepolicy_orchestrator
3.5.0
mcafeeepolicy_orchestrator
3.6.0
mcafeeepolicy_orchestrator
3.6.1
mcafeeepolicy_orchestrator
4.0
mcafeeepolicy_orchestrator
4.5.0
mcafeeepolicy_orchestrator
4.5.3
mcafeeepolicy_orchestrator
4.5.4
mcafeeepolicy_orchestrator
4.5.5
mcafeeepolicy_orchestrator
4.6.0
mcafeeepolicy_orchestrator
4.6.1
mcafeeepolicy_orchestrator
4.6.2
mcafeeepolicy_orchestrator
4.6.3
mcafeeepolicy_orchestrator
4.6.4
mcafeeepolicy_orchestrator
4.6.5
𝑥
= Vulnerable software versions