CVE-2016-1308: SQL Injection
SQL injection vulnerability in Cisco Unified Communications Manager 10.5(2.13900.9) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCux99227.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1308?
CVE-2016-1308 is classified as a critical severity vulnerability due to its potential for remote SQL injection attacks.
Who is affected by CVE-2016-1308?
CVE-2016-1308 affects remote authenticated users of Cisco Unified Communications Manager version 10.5(2.13900.9).
How do I fix CVE-2016-1308?
To mitigate CVE-2016-1308, users should apply the latest patches provided by Cisco for Unified Communications Manager.
What type of attack does CVE-2016-1308 enable?
CVE-2016-1308 enables remote authenticated users to execute arbitrary SQL commands through crafted URLs.
What is the potential impact of CVE-2016-1308?
The potential impact of CVE-2016-1308 includes unauthorized access to sensitive data and potential database compromise.