McAfee ePolicy Orchestrator 4.6.0-4.6.5 (ePowner) – Multiple vulnerabilities
This tool registers a rogue agent on the ePo server and then takes advantage of the following vulnerabilities to perform multiple actions: CVE-2013-0140 (Pre-auth SQL Injection) and CVE-2013-0141 (Pre-auth Directory Path Traversal). The tool manages the following actions, called 'mode': Register a new agent on the ePo server, Check the SQL Injection vulnerability, Add a new web admin account into the DB, Retrieve various information from the database, Retrieve the installation path of ePo software, Retrieve and decrypt cached domain credentials from ePo database, Wipe our traces from the database and file system, Perform remote command execution on the ePo server, Upload files on the ePo server, and Deploy commands or softwares on clients.