CVE-2013-0141: Path Traversal
Directory traversal vulnerability in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to upload arbitrary files via a crafted request over the Agent-Server communication channel, as demonstrated by writing to the Software/ directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0141?
CVE-2013-0141 is considered a critical severity vulnerability due to its potential for unauthorized file uploads.
How do I fix CVE-2013-0141?
To fix CVE-2013-0141, upgrade McAfee ePolicy Orchestrator to version 4.5.7 or 4.6.6 or later.
What software versions are affected by CVE-2013-0141?
CVE-2013-0141 affects McAfee ePolicy Orchestrator versions prior to 4.5.7 and 4.6.x before 4.6.6.
What type of attack can exploit CVE-2013-0141?
CVE-2013-0141 can be exploited by remote attackers leveraging directory traversal to upload arbitrary files.
Is CVE-2013-0141 publicly known?
Yes, CVE-2013-0141 is a publicly documented vulnerability, disclosed in 2013.