Cisco Unified Communications Domain Manager CVE-2014-8010 Command Injection Vulnerability
BID:71563
Info
Cisco Unified Communications Domain Manager CVE-2014-8010 Command Injection Vulnerability
| Bugtraq ID: | 71563 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8010 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2014 12:00AM |
| Updated: | Dec 09 2014 12:00AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Unified Communications Domain Manager CVE-2014-8010 Command Injection Vulnerability
Cisco Unified Communications Domain Manager is prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands with the privileges of the web server process.
This issue is being tracked by Cisco bug ID CSCuq50205.
Cisco Unified Communications Domain Manager is prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands with the privileges of the web server process.
This issue is being tracked by Cisco bug ID CSCuq50205.
Exploit / POC
Cisco Unified Communications Domain Manager CVE-2014-8010 Command Injection Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Cisco Unified Communications Domain Manager CVE-2014-8010 Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Unified Communications Domain Manager CVE-2014-8010 Command Injection Vulnerability
References:
References:
- Cisco Homepage (Cisco )