CVE-2018-6660
Summary
| CVE | CVE-2018-6660 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-02 13:29:00 UTC |
| Updated | 2023-11-07 03:00:00 UTC |
| Description | Directory Traversal vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows administrators to use Windows alternate data streams, which could be used to bypass the file extensions, via not properly validating the path when exporting a particular XML file. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Epolicy Orchestrator | 5.3.0 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.3.1 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.3.2 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.9.0 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.3.0 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.3.1 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.3.2 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.9.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| McAfee Security Bulletin - ePolicy Orchestrator update fixes Cross-Site Scripting (CVE-2018-6659) and Directory Traversal (CVE-2018-6660) vulnerabilities | CONFIRM | kc.mcafee.com | Vendor Advisory |
| McAfee ePolicy Orchestrator Directory Traversal and Cross Site Scripting Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| McAfee ePolicy Orchestrator Flaws Let Remote Users Conduct Cross-Site Scripting Attacks and Remote Authenticated Administrators Modify Data and Deny Service - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.