Cisco Unified Communication Manager Multiple Vulnerabilities
BID:28690
Info
Cisco Unified Communication Manager Multiple Vulnerabilities
| Bugtraq ID: | 28690 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Apr 08 2008 12:00AM |
| Updated: | Apr 16 2008 12:28AM |
| Credit: | VoIPshield |
| Vulnerable: |
Cisco Unified Communications Manager 5.1(3a) Cisco Unified Communications Manager 5.1(2b) Cisco Unified Communications Manager 5.1(2a) Cisco Unified Communications Manager 5.1(2) Cisco Unified Communications Manager 5.1(1) Cisco Unified Communications Manager 5.0 |
| Not Vulnerable: | |
Discussion
Cisco Unified Communication Manager Multiple Vulnerabilities
Cisco Unified Communication Manager is prone to 11 vulnerabilities, including an SQL-injection issue, multiple information-disclosure issues, and multiple unauthorized-access issues.
A successful exploit may allow an attacker to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, obtain sensitive information, gain unauthorized access to the affected application, or cause the application to crash. Other attacks are also possible.
Cisco Unified Communication Manager is prone to 11 vulnerabilities, including an SQL-injection issue, multiple information-disclosure issues, and multiple unauthorized-access issues.
A successful exploit may allow an attacker to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, obtain sensitive information, gain unauthorized access to the affected application, or cause the application to crash. Other attacks are also possible.
Exploit / POC
Cisco Unified Communication Manager Multiple Vulnerabilities
An attacker can exploit some of these issues through a browser. Specific exploits are not required for some of these issues.
An attacker can exploit some of these issues through a browser. Specific exploits are not required for some of these issues.
Solution / Fix
Cisco Unified Communication Manager Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco Unified Communication Manager Multiple Vulnerabilities
References:
References:
- Address Book SQL Injection (VoIPshield)
- Cisco Unified Communication Manager Homepage (Cisco)
- UCM Multiple Hardcoded Passwords (VoIPshield)
- Unauthenticated Alarm Application Access (VoIPshield)
- Unauthenticated Balancer Access (VoIPshield)
- Unauthenticated Call Server Link Access (VoIPshield)
- Unauthenticated Cisco Serviceability Access (VoIPshield)
- Unauthenticated Extension Mobility Web Access (VoIPshield)
- Unauthenticated License File Access (VoIPshield)
- Unauthenticated pktCap Access (VoIPshield)
- Unauthenticated Plugin Access (VoIPshield)
- Unencrypted Authenticated Access (VoIPshield)