7.5
CVSSv2

CVE-2011-0960

Published: 20/05/2011 Updated: 14/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) prior to 8.6 allow remote malicious users to execute arbitrary SQL commands via (1) the CCMs parameter to iptm/PRTestCreation.do or (2) the ccm parameter to iptm/TelePresenceReportAction.do, aka Bug ID CSCtn61716.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified operations manager 2.2

cisco unified operations manager 2.0

cisco unified operations manager 2.0.1

cisco unified operations manager

cisco unified operations manager 2.0.2

cisco unified operations manager 1.1

cisco unified operations manager 2.3

cisco unified operations manager 2.1

cisco unified operations manager 8.0

cisco unified operations manager 2.0.3

Exploits

Sense of Security - Security Advisory - SOS-11-006 Release Date 18-May-2011 Last Update - Vendor Notification Date 28-Feb-2011 Product Cisco Unified Operations Manager Common Services Framework Help Servlet Common Service ...
Cisco Unified Operations Manager suffers from cross site scripting, remote SQL injection, and directory traversal vulnerabilities Versions 80 and 85 are affected ...