First published: Thu Feb 14 2008(Updated: )
SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | =5.0_4 | |
Cisco Unified CallManager | =5.0\(2\) | |
Cisco Unified Communications Manager | =5.0_4a | |
Cisco Unified Communications Manager | =5.0 | |
Cisco Unified CallManager | =5.0\(3\) | |
Cisco Unified CallManager | =5.0\(3a\) | |
Cisco Unified Communications Manager | =5.0_1 | |
Cisco Unified Communications Manager | =6.1 | |
Cisco Unified Communications Manager | =5.0_4a_su1 | |
Cisco Unified CallManager | =5.0_4a | |
Cisco Unified CallManager | =6.0 | |
Cisco Unified Communications Manager | =5.0_3a | |
Cisco Unified CallManager | =5.0\(1\) | |
Cisco Unified CallManager | =5.0\(4\) | |
Cisco Unified Communications Manager | =5.0_3 | |
Cisco Unified CallManager | =5.0 | |
Cisco Unified Communications Manager | =5.0_2 | |
Cisco Unified Communications Manager | =6.0_1 | |
Cisco Unified CallManager | =5.1 | |
Cisco Unified Communications Manager | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.