CVE-2011-1610
published 2011-05-03CVE-2011-1610: Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM…
PriorityP352medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
24.82%
97.6th percentile
Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or (3) n parameter, aka Bug ID CSCtj42064.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_cisco6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Potential SQL Injection Vulnerability
vendor_cisco·2011-04-27·CVSS 6.4
CVE-2011-1610 [MEDIUM] CWE-264 Cisco Unified Communications Manager Potential SQL Injection Vulnerability
Cisco Unified Communications Manager Potential SQL Injection Vulnerability
Cisco Unified Communications Manager contains a vulnerability that could allow an unauthenticated, remote attacker to conduct SQL injection on a vulnerable system.
The vulnerability is in a JavaServer Pages (JSP) script due to insufficient checks on user-supplied input. An unauthenticated, remote attacker could exploit this vulnerability by submitting crafted parameters that contain malicious SQL commands to the vulnerable script. The processing of these parameters could allow the attacker to execute arbitrary SQL commands that could lead to a modification of sensitive information in the underlying database.
Cisco has confirmed this vulnerability and has released updated software.
To exploit the vulnerability, an
Cisco
Multiple Vulnerabilities in Cisco Unified Communications Manager
vendor_cisco
CVE-2011-1610 Multiple Vulnerabilities in Cisco Unified Communications Manager
CVE-2011-1610: Multiple Vulnerabilities in Cisco Unified Communications Manager
Cisco Unified Communications Manager (previously known as Cisco CallManager) contains the following vulnerabilities: Three (3) denial of service (DoS) vulnerabilities that affect Session Initiation Protocol (SIP) services Directory transversal vulnerability Two (2) SQL injection vulnerabilities Cisco has released free software updates for affected Cisco Unified Communications Manager versions to address the vulnerabilities. A workaround exists only for the SIP DoS vulnerabilities. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110427-cucm .
Bug IDs: CSCti42904, CSCth39586, CSCtg62855, CSCti81603, CSCtg85647
GHSA
GHSA-w5r2-842q-f7rx: Multiple SQL injection vulnerabilities in xmldirectorylist
ghsa_unreviewed·2022-05-14
CVE-2011-1610 [MEDIUM] CWE-89 GHSA-w5r2-842q-f7rx: Multiple SQL injection vulnerabilities in xmldirectorylist
Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or (3) n parameter, aka Bug ID CSCtj42064.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/fulldisclosure/2011-05/0051.htmlhttp://secunia.com/advisories/44331http://www.cisco.com/en/US/products/products_security_advisory09186a0080b79904.shtmlhttp://www.securityfocus.com/archive/1/517727/100/0/threadedhttp://www.securityfocus.com/bid/47607http://www.securitytracker.com/id?1025449http://www.vupen.com/english/advisories/2011/1122http://zerodayinitiative.com/advisories/ZDI-11-143/https://exchange.xforce.ibmcloud.com/vulnerabilities/67126http://archives.neohapsis.com/archives/fulldisclosure/2011-05/0051.htmlhttp://secunia.com/advisories/44331http://www.cisco.com/en/US/products/products_security_advisory09186a0080b79904.shtmlhttp://www.securityfocus.com/archive/1/517727/100/0/threadedhttp://www.securityfocus.com/bid/47607http://www.securitytracker.com/id?1025449http://www.vupen.com/english/advisories/2011/1122http://zerodayinitiative.com/advisories/ZDI-11-143/https://exchange.xforce.ibmcloud.com/vulnerabilities/67126
2011-05-03
Published