Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-3006

Опубликовано: 10 авг. 2011
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

The MyAsUtil ActiveX control in MyAsUtil5.2.0.603.dll in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to bypass the MyASUtil.SecureObjectFactory.CreateSecureObject domain execution policy using a cross-site scripting (XSS) attack, execute arbitrary code using the MyASUtil.InstallInfo.RunUserProgram function, and possibly conduct other unspecified attacks.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mcafee:saas_endpoint_protection:*:*:*:*:*:*:*:*
Версия до 5.2.1 (включая)

EPSS

Процентиль: 76%
0.00986
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
больше 3 лет назад

The MyAsUtil ActiveX control in MyAsUtil5.2.0.603.dll in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to bypass the MyASUtil.SecureObjectFactory.CreateSecureObject domain execution policy using a cross-site scripting (XSS) attack, execute arbitrary code using the MyASUtil.InstallInfo.RunUserProgram function, and possibly conduct other unspecified attacks.

EPSS

Процентиль: 76%
0.00986
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-264