CVE-2014-0726: SQL Injection
Published Feb 13, 2014
·Updated
SQL injection vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum05326.
Affected Software
2 affected components
Cisco Unified Communications Manager<=10.0\(1\)
Cisco Unified Communications Manager=10.0
Event History
Feb 13, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·05:24 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0726?
CVE-2014-0726 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2014-0726?
To fix CVE-2014-0726, upgrade Cisco Unified Communications Manager to version 10.0(2) or later.
3
What software is affected by CVE-2014-0726?
CVE-2014-0726 affects Cisco Unified Communications Manager versions up to and including 10.0(1).
4
Can CVE-2014-0726 be exploited remotely?
Yes, CVE-2014-0726 can be exploited remotely by attackers via a crafted URL.
5
What types of attacks can CVE-2014-0726 facilitate?
CVE-2014-0726 can facilitate attacks allowing remote execution of arbitrary SQL commands.