8.5
CVSSv2

CVE-2011-1609

Published: 03/05/2011 Updated: 17/08/2017
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 855
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x prior to 6.1(5)su2, 7.x prior to 7.1(5)su1, 8.0 prior to 8.0(3), and 8.5 prior to 8.5(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtg85647.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager 6.0

cisco unified communications manager 6.1\\(3b\\)su1

cisco unified communications manager 6.1\\(4\\)su1

cisco unified communications manager 6.1\\(4a\\)su2

cisco unified communications manager 6.1\\(4a\\)

cisco unified communications manager 6.1\\(3a\\)

cisco unified communications manager 6.1\\(4\\)

cisco unified communications manager 6.1\\(1\\)

cisco unified communications manager 6.1\\(2\\)su1

cisco unified communications manager 6.1\\(2\\)

cisco unified communications manager 6.1\\(3b\\)

cisco unified communications manager 6.1\\(5\\)

cisco unified communications manager 6.1\\(5\\)su1

cisco unified communications manager 6.1\\(2\\)su1a

cisco unified communications manager 6.1\\(1b\\)

cisco unified communications manager 6.1\\(1a\\)

cisco unified communications manager 6.1\\(3\\)

cisco unified communications manager 7.1\\(3a\\)

cisco unified communications manager 7.1\\(3\\)

cisco unified communications manager 7.1\\(5b\\)

cisco unified communications manager 7.1\\(5a\\)

cisco unified communications manager 7.1\\(2a\\)su1

cisco unified communications manager 7.1\\(2b\\)

cisco unified communications manager 7.1\\(5\\)

cisco unified communications manager 7.1\\(3b\\)su2

cisco unified communications manager 7.0\\(2\\)

cisco unified communications manager 7.0\\(1\\)su1

cisco unified communications manager 7.0\\(2a\\)su1

cisco unified communications manager 7.1\\(3b\\)su1

cisco unified communications manager 7.1\\(3a\\)su1a

cisco unified communications manager 7.0\\(2a\\)su2

cisco unified communications manager 7.0\\(1\\)su1a

cisco unified communications manager 7.1\\(3a\\)su1

cisco unified communications manager 7.1\\(3b\\)

cisco unified communications manager 7.1\\(5\\)su1a

cisco unified communications manager 7.1\\(5\\)su1

cisco unified communications manager 7.0\\(2a\\)

cisco unified communications manager 7.1\\(2a\\)

cisco unified communications manager 8.0\\(3a\\)su2

cisco unified communications manager 8.5

cisco unified communications manager 8.0\\(3\\)

cisco unified communications manager 8.0\\(2c\\)su1

cisco unified communications manager 8.0\\(2c\\)

cisco unified communications manager 8.0\\(3a\\)

cisco unified communications manager 8.0\\(3a\\)su1

Vendor Advisories

Cisco Unified Communications Manager (previously known as Cisco CallManager) contains the following vulnerabilities: Three (3) denial of service (DoS) vulnerabilities that affect Session Initiation Protocol (SIP) services Directory transversal vulnerability Two (2) SQL injection vulnerabilities Cisco has released free software upd ...
Check Point Reference: CPAI-2011-0748 Date Published: 27 Mar 2024 Severity: High ...

Exploits

source: wwwsecurityfocuscom/bid/47607/info Cisco Unified Communications Manager is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting this issue could allow an authenticated attacker to compromise the affected device, access or modify da ...