First published: Tue Dec 31 2013(Updated: )
SQL injection vulnerability in the web interface in Cisco Unified Presence Server allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuh35615.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Presence Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6983 is regarded as a high severity vulnerability due to its potential to allow remote authenticated users to execute arbitrary SQL commands.
To fix CVE-2013-6983, it is recommended to apply the latest patches and updates provided by Cisco for the Unified Presence Server.
CVE-2013-6983 affects Cisco Unified Presence Server installations where remote authenticated users can access the web interface.
CVE-2013-6983 is classified as an SQL injection vulnerability.
Yes, CVE-2013-6983 can potentially lead to data breaches by allowing attackers to execute arbitrary SQL commands and access sensitive information.