CVE-2013-4882 EXPLOIT
6.5
MEDIUM · CVSS 2.0 · EPSS 3.9% (pctl 90)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (ePO) extension for McAfee Agent (MA) 4.5 and 4.6, allow remote authenticated users to execute arbitrary SQL commands via the uid parameter to (1) core/showRegisteredTypeDetails.do and (2) EPOAGENTMETA/DisplayMSAPropsDetail.do, a different vulnerability than CVE-2013-0140.
Scoring
| CVSS | 6.5 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
| EPSS | 3.91% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-07-22 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| mcafee | epolicy orchestrator |
| mcafee | epolicy orchestrator agent |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | McAfee ePO 4.6.6 - Multiple Vulnerabilities | 2013-07-13 |
References
→ the Explorer · watch your stack · NVD