2011-05-04 00:55:02 2018-10-09 21:31:23

Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or (3) n parameter, aka Bug ID CSCtj42064.

Vector

NETWORK

Complexity

LOW

Authentication

NONE

Confidentiality

PARTIAL

Integrity

PARTIAL

Availability

NONE
Cisco Unified Communications Manager 8.0(3a) Cisco Unified Communications Manager 8.0(2c)su1 Cisco Unified Communications Manager 8.0(3) Cisco Unified Communications Manager 8.0(2c) Cisco Unified Communications Manager 8.0 Cisco Unified Communications Manager 7.1(5b)su3 Cisco Unified Communications Manager 7.1(5b)su2 Cisco Unified Communications Manager 7.1(5a) Cisco Unified Communications Manager 7.1(5b) Cisco Unified Communications Manager 7.1(5)su1a Cisco Unified Communications Manager 7.1(5)su1 Cisco Unified Communications Manager 7.1(5) Cisco Unified Communications Manager 7.1(3b)su2 Cisco Unified Communications Manager 7.1(3b)su1 Cisco Unified Communications Manager 7.1(3b) Cisco Unified Communications Manager 7.1(3a)su1a Cisco Unified Communications Manager 7.1(3a)su1 Cisco Unified Communications Manager 7.1(3a) Cisco Unified Communications Manager 7.1(3) Cisco Unified Communications Manager 7.1(2b)su1 Cisco Unified Communications Manager 7.1(2b) Cisco Unified Communications Manager 7.1(2a)su1 Cisco Unified Communications Manager 7.1(2a) Cisco Unified Communications Manager 7.0(2a)su2 Cisco Unified Communications Manager 7.0(2a)su1 Cisco Unified Communications Manager 7.0(2a) Cisco Unified Communications Manager 7.0(2) Cisco Unified Communications Manager 7.0(1)su1a Cisco Unified Communications Manager 6.1(5)su2 Cisco Unified Communications Manager 7.0(1)su1 Cisco Unified Communications Manager 6.1(5)su1 Cisco Unified Communications Manager 6.1(5) Cisco Unified Communications Manager 6.1(4a) Cisco Unified Communications Manager 6.1(4a)su2 Cisco Unified Communications Manager 6.1(4)su1 Cisco Unified Communications Manager 6.1(4) Cisco Unified Communications Manager 6.1(3b)su1 Cisco Unified Communications Manager 6.1(3b) Cisco Unified Communications Manager 6.1(3) Cisco Unified Communications Manager 6.1(3a) Cisco Unified Communications Manager 6.1(2)su1a Cisco Unified Communications Manager 6.1(2)su1 Cisco Unified Communications Manager 6.1(2) Cisco Unified Communications Manager 6.1(1b) Cisco Unified Communications Manager 6.1(1a) Cisco Unified Communications Manager 6.1(1) Cisco Unified Communications Manager 6.0 Cisco Unified Communications Manager 8.0(3a)su1