CVE-2018-6669

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
20/12/2018
Last modified:
07/11/2023

Description

A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or local user to execute blacklisted files through an ASP.NET form.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mcafee:application_change_control:*:*:*:*:*:*:*:* 7.0.1 (including)