CVE-2013-7104: OS Command Injection
McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands by specifying them in the value attribute in a (1) Command or (2) Script XML element. NOTE: this issue can be combined with CVE-2013-7092 to allow remote attackers to execute commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7104?
CVE-2013-7104 is classified as a critical vulnerability allowing arbitrary command execution.
How does CVE-2013-7104 affect McAfee Email Gateway 7.6?
CVE-2013-7104 allows remote authenticated administrators to execute arbitrary commands via XML elements.
How do I fix CVE-2013-7104?
To mitigate CVE-2013-7104, apply the latest security patches provided by McAfee for Email Gateway 7.6.
Who can exploit CVE-2013-7104?
CVE-2013-7104 can be exploited by remote authenticated administrators with sufficient access rights.
What software versions are affected by CVE-2013-7104?
CVE-2013-7104 specifically affects McAfee Email Gateway version 7.6.