CVE-2013-4883
Summary
| CVE | CVE-2013-4883 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-07-22 11:21:15 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extension for the McAfee Agent (MA) 4.5 through 4.6, allow remote attackers to inject arbitrary web script or HTML via the (1) instanceId parameter core/loadDisplayType.do; (2) instanceId or (3) monitorUrl parameter to console/createDashboardContainer.do; uid parameter to (4) ComputerMgmt/sysDetPanelBoolPie.do or (5) ComputerMgmt/sysDetPanelSummary.do; (6) uid, (7) orion.user.security.token, or (8) ajaxMode parameter to ComputerMgmt/sysDetPanelQry.do; or (9) uid, (10) orion.user.security.token, or (11) ajaxMode parameter to ComputerMgmt/sysDetPanelSummary.do. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Epolicy Orchestrator | 4.6.0 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 4.6.1 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 4.6.2 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 4.6.3 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 4.6.4 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 4.6.5 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | All | All | All | All |
| Application | Mcafee | Epolicy Orchestrator Agent | 4.5 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator Agent | 4.6 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| osvdb.org/95191 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/95190 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| McAfee ePolicy Orchestrator Input Validation Flaws Permit Cross-Site Scripting and SQL Injection Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| McAfee KnowledgeBase - Multiple vulnerabilities in ePO 4.6.6 and earlier | af854a3a-2127-422b-91ae-364da2661108 | kc.mcafee.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/95187 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/95188 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/95189 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.