6.8
CVSSv2

CVE-2015-0753

Published: 29/05/2015 Updated: 04/01/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Cisco Unified Email Interaction Manager (EIM) and Unified Web Interaction Manager (WIM) 9.0(2) allows remote malicious users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuu30028.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified web and e-mail interaction manager 9.0\\(2\\)

Vendor Advisories

A vulnerability in the Cisco Unified Email Interaction Manager (EIM) and Cisco Unified Web Interaction Manager (WIM) interface could allow an unauthenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries The vulnerability is due to a lack of input validation on user-supplied input in SQL queries ...