Cisco Unified Communications Manager CVE-2013-3412 SQL Injection Vulnerability
BID:61295
Info
Cisco Unified Communications Manager CVE-2013-3412 SQL Injection Vulnerability
| Bugtraq ID: | 61295 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3412 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2013 12:00AM |
| Updated: | Jul 19 2013 04:43PM |
| Credit: | Lexfo |
| Vulnerable: |
Cisco Unified Communications Manager 8.6.3 Cisco Unified Communications Manager 8.6(2a)su1 Cisco Unified Communications Manager 8.6 Cisco Unified Communications Manager 8.5(1)SU2 Cisco Unified Communications Manager 8.5(1)SU1 Cisco Unified Communications Manager 8.5(1) Cisco Unified Communications Manager 8.5 Cisco Unified Communications Manager 8.0(3a)su3 Cisco Unified Communications Manager 8.0(3a)su3 Cisco Unified Communications Manager 8.0(3a)SU2 Cisco Unified Communications Manager 8.0(3a)su1 Cisco Unified Communications Manager 8.0(3a) Cisco Unified Communications Manager 8.0(3) Cisco Unified Communications Manager 8.0(2C)Su1 Cisco Unified Communications Manager 8.0(2C) Cisco Unified Communications Manager 8.0(1) Cisco Unified Communications Manager 7.1(5b)su5 Cisco Unified Communications Manager 7.1(5b)SU4 Cisco Unified Communications Manager 7.1(5b)su3 Cisco Unified Communications Manager 7.1(5b)SU2 Cisco Unified Communications Manager 7.1(5B) Cisco Unified Communications Manager 7.1(5A) Cisco Unified Communications Manager 7.1(5)Su1a Cisco Unified Communications Manager 7.1(5)Su1 Cisco Unified Communications Manager 7.1(5) Cisco Unified Communications Manager 7.1(3b)su2 Cisco Unified Communications Manager 7.1(3b)su1 Cisco Unified Communications Manager 7.1(3B) Cisco Unified Communications Manager 7.1(3A)Su1a Cisco Unified Communications Manager 7.1(3a)su1 Cisco Unified Communications Manager 7.1(3A) Cisco Unified Communications Manager 7.1(3) |
| Not Vulnerable: | |
Discussion
Cisco Unified Communications Manager CVE-2013-3412 SQL Injection Vulnerability
Cisco Unified Communications Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an authenticated attacker to compromise the affected application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue is tracked by Cisco Bug ID CSCuh81766.
Cisco Unified Communications Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an authenticated attacker to compromise the affected application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue is tracked by Cisco Bug ID CSCuh81766.
Exploit / POC
Cisco Unified Communications Manager CVE-2013-3412 SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The researchers who discovered this issue have developed an exploit code to demonstrate it. Please see the references for more information.
Attackers can use a browser to exploit this issue.
The researchers who discovered this issue have developed an exploit code to demonstrate it. Please see the references for more information.
Solution / Fix
Cisco Unified Communications Manager CVE-2013-3412 SQL Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco Unified Communications Manager CVE-2013-3412 SQL Injection Vulnerability
References:
References:
- Cisco Homepage (Cisco)