RSS   Podatności dla 'Policy auditor'   RSS

2021-11-23
 
CVE-2021-31851

CWE-79
 

 
A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the profileNodeID request parameters. The malicious script is reflected unmodified into the Policy Auditor web-based interface which could lead to the extraction of end user session token or login credentials. These may be used to access additional security-critical applications or conduct arbitrary cross-domain requests.

 
 
CVE-2021-31852

CWE-79
 

 
A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the UID request parameter. The malicious script is reflected unmodified into the Policy Auditor web-based interface which could lead to the extract of end user session token or login credentials. These may be used to access additional security-critical applications or conduct arbitrary cross-domain requests.

 

 >>> Vendor: Mcafee 136 Produkty
Virusscan
Webshield smtp
Remote desktop 32
E-business server
Asap virusscan
Epolicy orchestrator
Entercept agent
Antivirus engine
Freescan
Security installer control system
Internet security suite
Intrushield security management system
Epolicy orchestrator agent
Antispyware
Mcinsctl.dll
Virusscan security center
Common management agent
Virusscan enterprise
Virex
Asset manager
Personal firewall plus
Privacy service
Quickclean
Security center
Spamkiller
Wireless home network security
Enterprise security manager
Scan engine
Protectionpilot
Network agent
Endpoint security
Neotrace
Visual trace
Securitycenter agent
Internet security
Agent
CMA
Mcafee framework
Encrypted usb manager
Safeboot device encryption
Active virus defense
Active virusscan
Email gateway
Securityshield for email servers
Securityshield for microsoft isa server
Securityshield for microsoft sharepoint
Total protection
Total protection for endpoint
Virusscan commandline
Virusscan plus
Virusscan usb
Groupshield
Gateway
Smartfilter
Email and web security appliance
Intrushield network security manager
Anti-virus plus
Web gateway
Secure mail
Unified threat management firewall firmware
Data loss prevention
Saas endpoint protection
Linuxshield
Host data loss prevention
Firewall reporter
Email and web security
Enterprise mobility manager
Enterprise mobility manager agent
Application control
Change control
Mcafee virtual technician
Epo mcafee virtual technician
Total protection 2010
Vulnerability manager
Superscan
Cloud identity manager
Cloud single sign on
Network security manager
Network data loss prevention
Endpoint encryption for files and folders
Mcafee file and removable media protection
File and removable media protection
Data loss prevention endpoint
Mcafee agent
Advanced threat defense
Epo deep command
Threat intelligence exchange
Enterprise security manager/log manager
Enterprise security manager/receiver
Mcafee enterprise security manager
File lock
Livesafe
Active response
Data exchange layer
Host intrusion prevention
Smartfilter administration
Security information and event management
Security scan plus
Host intrusion prevention services
Cloud analysis and deconstructive services
Zobacz wszystkie produkty dla producenta Mcafee


Copyright 2024, cxsecurity.com

 

Back to Top