Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
McAfee Security ePolicy Orchestrator MSDE SA帐户信息泄露漏洞
Vulnerability Description
McAfee Security ePolicy Orchestrator是一款企业级反病毒管理工具。ePolicy Orchestrator是策略驱动配置,并包含报告工具。 McAfee ePolicy Orchestrator会泄露Microsoft Data Engine安装的管理员帐户信息,远程攻击者可以利用这个漏洞通过特殊HTTP请求获得这些敏感信息。 通过发送特殊构建的HTTP请求给ePO服务器,服务器会以服务器配置文件的内容进行应答,配置文件包含了MSDE安装的数据库管理员用户名和加密密码。加
CVSS Information
N/A
Vulnerability Type
N/A