CVE-2013-7092: SQL Injection
Multiple SQL injection vulnerabilities in /admin/cgi-bin/rpc/doReport/18 in McAfee Email Gateway 7.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) eventscol, (2) eventid, (3) reason, (4) eventsorder, (5) emailstatusorder, or (6) emailstatuscol JSON keys.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7092?
CVE-2013-7092 is classified as a critical vulnerability due to the potential for remote SQL command execution.
How do I fix CVE-2013-7092?
To mitigate CVE-2013-7092, upgrade McAfee Email Gateway to version 7.7 or later, which includes patches for these vulnerabilities.
Who is affected by CVE-2013-7092?
CVE-2013-7092 affects McAfee Email Gateway version 7.6 primarily targeted at remote authenticated users.
What are the main attack vectors for CVE-2013-7092?
The main attack vectors for CVE-2013-7092 include SQL injection through various JSON keys in the doReport RPC endpoint.
What can an attacker achieve with CVE-2013-7092?
An attacker exploiting CVE-2013-7092 can execute arbitrary SQL commands, compromising the database integrity and confidentiality.