CVE-2011-1610: SQL Injection
Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or (3) n parameter, aka Bug ID CSCtj42064.
Affected Software
Event History
Frequently Asked Questions
What are the SQL injection vulnerabilities associated with CVE-2011-1610?
CVE-2011-1610 includes multiple SQL injection vulnerabilities in the xmldirectorylist.jsp file of the embedded Apache HTTP Server in various versions of Cisco Unified Communications Manager.
What versions of Cisco Unified Communications Manager are affected by CVE-2011-1610?
The vulnerability affects Cisco Unified Communications Manager versions prior to 6.1(5)su3, 7.1(5)su4, 8.0(3a)su2, and 8.5(1)su1.
How can administrators mitigate the risks of CVE-2011-1610?
Administrators can mitigate CVE-2011-1610 by upgrading Cisco Unified Communications Manager to the latest patched versions.
What impact can CVE-2011-1610 have on affected systems?
Successful exploitation of CVE-2011-1610 can allow remote attackers to execute arbitrary SQL commands on the underlying database, potentially leading to data breach or system compromise.
Is there a public advisory for CVE-2011-1610?
Yes, Cisco has released security advisories that detail the vulnerabilities and the necessary steps for remediation for CVE-2011-1610.