6.4
CVSSv2

CVE-2011-1610

Published: 03/05/2011 Updated: 09/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x prior to 6.1(5)su3, 7.x prior to 7.1(5)su4, 8.0 prior to 8.0(3a)su2, and 8.5 prior to 8.5(1)su1 allow remote malicious users to execute arbitrary SQL commands via the (1) f, (2) l, or (3) n parameter, aka Bug ID CSCtj42064.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager 6.1\\(3b\\)su1

cisco unified communications manager 6.1\\(4a\\)

cisco unified communications manager 6.1\\(4a\\)su2

cisco unified communications manager 6.1\\(1\\)

cisco unified communications manager 6.1\\(2\\)

cisco unified communications manager 6.1\\(2\\)su1a

cisco unified communications manager 6.1\\(3b\\)

cisco unified communications manager 6.1\\(5\\)

cisco unified communications manager 6.1\\(3a\\)

cisco unified communications manager 6.1\\(4\\)

cisco unified communications manager 6.1\\(2\\)su1

cisco unified communications manager 6.1\\(5\\)su1

cisco unified communications manager 6.1\\(5\\)su2

cisco unified communications manager 6.1\\(1b\\)

cisco unified communications manager 6.0

cisco unified communications manager 6.1\\(1a\\)

cisco unified communications manager 6.1\\(3\\)

cisco unified communications manager 6.1\\(4\\)su1

cisco unified communications manager 7.1\\(3a\\)

cisco unified communications manager 7.1\\(3\\)

cisco unified communications manager 7.1\\(5b\\)

cisco unified communications manager 7.1\\(5a\\)

cisco unified communications manager 7.1\\(2a\\)su1

cisco unified communications manager 7.1\\(2b\\)

cisco unified communications manager 7.1\\(5\\)

cisco unified communications manager 7.1\\(3b\\)su2

cisco unified communications manager 7.0\\(2\\)

cisco unified communications manager 7.0\\(1\\)su1

cisco unified communications manager 7.1\\(2b\\)su1

cisco unified communications manager 7.1\\(5b\\)su2

cisco unified communications manager 7.1\\(3b\\)su1

cisco unified communications manager 7.1\\(3a\\)su1a

cisco unified communications manager 7.0\\(2a\\)su1

cisco unified communications manager 7.0\\(2a\\)su2

cisco unified communications manager 7.0\\(1\\)su1a

cisco unified communications manager 7.1\\(5b\\)su3

cisco unified communications manager 7.1\\(3a\\)su1

cisco unified communications manager 7.1\\(3b\\)

cisco unified communications manager 7.1\\(5\\)su1a

cisco unified communications manager 7.1\\(5\\)su1

cisco unified communications manager 7.0\\(2a\\)

cisco unified communications manager 7.1\\(2a\\)

cisco unified communications manager 8.0\\(2c\\)

cisco unified communications manager 8.0\\(3a\\)

cisco unified communications manager 8.0\\(3a\\)su1

cisco unified communications manager 8.0

cisco unified communications manager 8.0\\(3\\)

cisco unified communications manager 8.0\\(2c\\)su1

Vendor Advisories

Cisco Unified Communications Manager (previously known as Cisco CallManager) contains the following vulnerabilities: Three (3) denial of service (DoS) vulnerabilities that affect Session Initiation Protocol (SIP) services Directory transversal vulnerability Two (2) SQL injection vulnerabilities Cisco has released free software upd ...
Cisco Unified Communications Manager contains a vulnerability that could allow an unauthenticated, remote attacker to conduct SQL injection on a vulnerable system The vulnerability is in a JavaServer Pages (JSP) script due to insufficient checks on user-supplied input An unauthenticated, remote attacker could exploit this vulnerability by submit ...
Check Point Reference: CPAI-2011-0743 Date Published: 6 Mar 2024 Severity: Medium ...

Exploits

VSR has provided details for exploitation of a SQL injection vulnerability in the Cisco Unified CM ...