漏洞标题
N/A
漏洞描述信息
Cisco Unified Communications Manager(Unified CM)和Cisco Unified Communications Manager会话管理 Edition(Unified CM SME)的网页管理界面的一个漏洞可能导致 authenticated 的远程攻击者对受影响的系统进行SQL注入攻击。
这个漏洞是由于用户输入验证不完善造成的。攻击者可以通过以只读或更高权限的用户身份验证应用程序,并向受影响的系统发送精心构造的HTTP请求来利用此漏洞。成功利用漏洞可能导致攻击者读取或修改底层数据库中的数据,或者提升其权限。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
N/A
漏洞描述信息
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by authenticating to the application as a user with read-only or higher privileges and sending crafted HTTP requests to an affected system. A successful exploit could allow the attacker to read or modify data in the underlying database or elevate their privileges.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
Cisco Unified Communications Manager SQL注入漏洞
漏洞描述信息
Cisco Unified Communications Manager(CUCM,Unified CM,CallManager)是美国思科(Cisco)公司的一款统一通信系统中的呼叫处理组件。该组件提供了一种可扩展、可分布和高可用的企业IP电话呼叫处理解决方案。 Cisco Unified Communications Manager和Cisco Unified Communications Manager Session Management Edition存在安全漏洞,该漏洞源于对用户提供的输入的验
CVSS信息
N/A
漏洞类别
SQL注入