7.5
CVSSv2

CVE-2014-0726

Published: 13/02/2014 Updated: 16/09/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM) 10.0(1) and previous versions allows remote malicious users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum05326.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager

cisco unified communications manager 10.0

Vendor Advisories

A vulnerability in the Cisco Unified Communications Manager (UCM) IP Manager Assistant (IPMA) interface could allow an unauthenticated, remote attacker to impact the integrity of the system by executing arbitrary SQL queries The vulnerability is due to a lack of input validation on user-supplied input within SQL queries An attacker could exploi ...