6.8
CVSSv2

CVE-2008-6573

Published: 01/04/2009 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES) in Avaya Avaya Communication Manager 3.x, 4.0, and 5.0 (1) allow remote malicious users to execute arbitrary SQL commands via unspecified vectors related to profiles in the SIP Personal Information Manager (SPIM) in the web interface; and allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to (2) permissions for SPIM profiles in the web interface and (3) a crafted SIP request to the SIP server.

Vulnerable Product Search on Vulmon Subscribe to Product

avaya communication manager

avaya communication manager 3.1.5

avaya communication manager 3.1.3

avaya communication manager 3.1.4

avaya communication manager 3.1.1

avaya communication manager 3.1.2

avaya communication manager 4.0

avaya communication manager 5.0