CVE-2003-0148

The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mcafee:epolicy_orchestrator:2.0:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:epolicy_orchestrator:2.5:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:epolicy_orchestrator:2.5:sp1:*:*:*:*:*:*
cpe:2.3:a:mcafee:epolicy_orchestrator:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:epolicy_orchestrator:3.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:44

Type Values Removed Values Added
References () http://www.atstake.com/research/advisories/2003/a073103-1.txt - Patch, Vendor Advisory () http://www.atstake.com/research/advisories/2003/a073103-1.txt - Patch, Vendor Advisory
References () http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp - Patch, Vendor Advisory () http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp - Patch, Vendor Advisory

Information

Published : 2003-08-27 04:00

Updated : 2024-11-20 23:44


NVD link : CVE-2003-0148

Mitre link : CVE-2003-0148

CVE.ORG link : CVE-2003-0148


JSON object : View

Products Affected

mcafee

  • epolicy_orchestrator