CVE-2008-0026
published 2008-02-14CVE-2008-0026: SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote…
PriorityP336medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EXPLOIT
EPSS
1.93%
77.7th percentile
SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v78v-p3w6-9x7h: SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5
ghsa_unreviewed·2022-05-01
CVE-2008-0026 [MEDIUM] CWE-89 GHSA-v78v-p3w6-9x7h: SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5
SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.
Cisco
SQL injection in Cisco Unified Communications Manager
vendor_cisco·2008-02-13·CVSS 6.5
CVE-2008-0026 [MEDIUM] CWE-200 SQL injection in Cisco Unified Communications Manager
SQL injection in Cisco Unified Communications Manager
Cisco Unified Communications Manager is vulnerable to a SQL Injection
attack in the parameter key of the admin and user
interface pages. A successful attack could allow an authenticated attacker to
access information such as usernames and password hashes that are stored in the
database.
Cisco has released software updates that address this vulnerability.
Common Vulnerabilities and Exposures (CVE) identifier
CVE-2008-0026
has been assigned to this vulnerability.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20080213-cucmsql.
Cisco
SQL injection in Cisco Unified Communications Manager
vendor_cisco
CVE-2008-0026 SQL injection in Cisco Unified Communications Manager
CVE-2008-0026: SQL injection in Cisco Unified Communications Manager
Cisco Unified Communications Manager is vulnerable to a SQL Injection attack in the parameter key of the admin and user interface pages. A successful attack could allow an authenticated attacker to access information such as usernames and password hashes that are stored in the database. Cisco has released software updates that address this vulnerability. Common Vulnerabilities and Exposures (CVE) identifier CVE-2008-0026 has been assigned to this vulnerability. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20080213-cucmsql .
CWE: CWE-200, CWE-200
Bug IDs: CSCsk64286, CSCsk64286
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/28932http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7c.shtmlhttp://www.securityfocus.com/bid/27775http://www.securitytracker.com/id?1019404http://www.vupen.com/english/advisories/2008/0542https://exchange.xforce.ibmcloud.com/vulnerabilities/40484http://secunia.com/advisories/28932http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7c.shtmlhttp://www.securityfocus.com/bid/27775http://www.securitytracker.com/id?1019404http://www.vupen.com/english/advisories/2008/0542https://exchange.xforce.ibmcloud.com/vulnerabilities/40484
2008-02-14
Published