McAfee ePolicy Orchestrator CVE-2013-0141 Unspecified Directory Traversal Vulnerability
BID:59505
Info
McAfee ePolicy Orchestrator CVE-2013-0141 Unspecified Directory Traversal Vulnerability
| Bugtraq ID: | 59505 |
| Class: | Unknown |
| CVE: |
CVE-2013-0141 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2013 12:00AM |
| Updated: | May 02 2014 03:59AM |
| Credit: | Jerome Nokin of Verizon Enterprise Solutions |
| Vulnerable: |
McAfee ePolicy Orchestrator (ePO) 4.5 |
| Not Vulnerable: | |
Discussion
McAfee ePolicy Orchestrator CVE-2013-0141 Unspecified Directory Traversal Vulnerability
McAfee ePolicy Orchestrator is prone to an unspecified directory-traversal vulnerability.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
The following versions are vulnerable:
McAfee ePolicy Orchestrator 4.5 through versions 4.5.6
McAfee ePolicy Orchestrator 4.6 through versions 4.6.5
McAfee ePolicy Orchestrator is prone to an unspecified directory-traversal vulnerability.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
The following versions are vulnerable:
McAfee ePolicy Orchestrator 4.5 through versions 4.5.6
McAfee ePolicy Orchestrator 4.6 through versions 4.6.5
Exploit / POC
McAfee ePolicy Orchestrator CVE-2013-0141 Unspecified Directory Traversal Vulnerability
Attackers can exploit this issue with a web browser or readily available tools.
The researcher who discovered this issue has created an exploit. Please see the references for more information.
Attackers can exploit this issue with a web browser or readily available tools.
The researcher who discovered this issue has created an exploit. Please see the references for more information.
Solution / Fix
McAfee ePolicy Orchestrator CVE-2013-0141 Unspecified Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
McAfee ePolicy Orchestrator CVE-2013-0141 Unspecified Directory Traversal Vulnerability
References:
References:
- ePolicy Orchestrator Home Page (Network Associates Inc.)