cbcvebase.
CVE-2011-4487
published 2012-03-01

CVE-2011-4487: SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6…

medium6.8CVSS 3.1
AVNACMAuNCPIPAP
SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allows remote attackers to execute arbitrary SQL commands via a crafted SCCP registration, aka Bug ID CSCtu73538.

Affected

91 ranges· showing 25
VendorProductVersion rangeFixed in
ciscobusiness_edition_3000_software
ciscobusiness_edition_3000_software
ciscobusiness_edition_3000_software
ciscobusiness_edition_3000_software
ciscobusiness_edition_5000_software
ciscobusiness_edition_5000_software
ciscobusiness_edition_5000_software
ciscobusiness_edition_5000_software
ciscobusiness_edition_5000_software
ciscobusiness_edition_5000_software
ciscobusiness_edition_5000_software
ciscobusiness_edition_6000_software
ciscobusiness_edition_6000_software
ciscobusiness_edition_6000_software
ciscobusiness_edition_6000_software
ciscobusiness_edition_6000_software
ciscobusiness_edition_6000_software
ciscobusiness_edition_6000_software
ciscobusiness_edition_6000_software
ciscobusiness_edition_6000_software
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager