CVE-2008-0026: SQL Injection
SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0026?
CVE-2008-0026 has a medium severity rating due to its potential for exploitation via SQL injection.
How do I fix CVE-2008-0026?
To fix CVE-2008-0026, update Cisco Unified CallManager/Communications Manager to version 5.1(3a) or later, and 6.1(1a) or later.
Who is affected by CVE-2008-0026?
CVE-2008-0026 affects remote authenticated users of Cisco Unified CallManager versions 5.0, 5.1, and 6.0 prior to the specified updates.
What kind of attack can exploit CVE-2008-0026?
CVE-2008-0026 can be exploited to execute arbitrary SQL commands, which can lead to unauthorized data access or modification.
Is there a workaround for CVE-2008-0026?
There is no official workaround for CVE-2008-0026; patching the software is the recommended mitigation.