peter bassill · operator
$ cve CVE-2013-5015 JSON

CVE-2013-5015 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 28.8% (pctl 98)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Edition 12.x before 12.1.4023.4080, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS28.76% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2014-02-14
Last modified2026-06-16

Affected (2)

VendorProduct
symantecendpoint protection manager
symantecprotection center

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD