6.5
CVSSv2

CVE-2008-0026

Published: 14/02/2008 Updated: 08/08/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 prior to 5.1(3a) and 6.0/6.1 prior to 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified callmanager 5.0\\(3\\)

cisco unified callmanager 5.0\\(3a\\)

cisco unified communications manager 5.0_2

cisco unified communications manager 5.0_3

cisco unified communications manager 6.1

cisco unified callmanager 5.0\\(1\\)

cisco unified callmanager 5.0\\(2\\)

cisco unified communications manager 5.0

cisco unified communications manager 5.0_1

cisco unified communications manager 6.0

cisco unified communications manager 6.0_1

cisco unified callmanager 5.0

cisco unified callmanager 5.1

cisco unified callmanager 6.0

cisco unified communications manager 5.0_4a

cisco unified communications manager 5.0_4a_su1

cisco unified callmanager 5.0\\(4\\)

cisco unified callmanager 5.0_4a

cisco unified communications manager 5.0_3a

cisco unified communications manager 5.0_4

Exploits

source: wwwsecurityfocuscom/bid/27775/info Cisco Unified Communications Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vuln ...
Portcullis Security Advisory - The Cisco Unified CallManager is vulnerable to multiple SQL injections in the user interface as well as in the administration interface Affected versions include 5042000-1, 51, 60, and 61 ...