CVE-2013-0140 | McAfee ePolicy Orchestrator up to 4.6.5 Agent DisplayMSAPropsDetail.do uid sql injection (SB10042 / VU#209131)
A vulnerability classified as critical was found in McAfee ePolicy Orchestrator up to 4.6.5. Affected by this vulnerability is an unknown functionality of the file /EPOAGENTMETA/DisplayMSAPropsDetail.do of the component Agent Handler. The manipulation of the argument uid leads to sql injection.
This vulnerability is known as CVE-2013-0140. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.