Vulnerability Description
McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands by specifying them in the value attribute in a (1) Command or (2) Script XML element. NOTE: this issue can be combined with CVE-2013-7092 to allow remote attackers to execute commands.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Email Gateway | 7.6 |
Related Weaknesses (CWE)
References
- http://osvdb.org/100581
- http://packetstormsecurity.com/files/124277/McAfee-Email-Gateway-7.6-Command-ExeExploit
- http://seclists.org/fulldisclosure/2013/Dec/18Exploit
- http://www.securityfocus.com/bid/64150
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90163
- http://osvdb.org/100581
- http://packetstormsecurity.com/files/124277/McAfee-Email-Gateway-7.6-Command-ExeExploit
- http://seclists.org/fulldisclosure/2013/Dec/18Exploit
- http://www.securityfocus.com/bid/64150
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90163
FAQ
What is CVE-2013-7104?
CVE-2013-7104 is a vulnerability with a CVSS score of 9.0 (HIGH). McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands by specifying them in the value attribute in a (1) Command or (2) Script XML element. NOTE: this issu...
How severe is CVE-2013-7104?
CVE-2013-7104 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-7104?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Email Gateway.