CVE-2013-3412
published 2013-07-18CVE-2013-3412: SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary SQL…
PriorityP336medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
0.96%
57.7th percentile
SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuh81766.
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Blind SQL Injection Vulnerability
vendor_cisco·2013-07-17·CVSS 6.5
CVE-2013-3412 [MEDIUM] CWE-89 Cisco Unified Communications Manager Blind SQL Injection Vulnerability
Cisco Unified Communications Manager Blind SQL Injection Vulnerability
A vulnerability in Cisco Unified Communication Manager (Unified CM) could allow an authenticated, remote attacker to execute a blind Structured Query Language (SQL) injection.
The vulnerability is due to improper validation of user-supplied requests by the Cisco Unified CM. An attacker could exploit this vulnerability by injecting SQL commands, which could allow the attacker to insert rows within the database.
Proof-of-concept code that demonstrates an exploit of this vulnerability is publicly available.
Cisco has confirmed the vulnerability in a security advisory; however, software updates are not yet available.
To exploit this vulnerability, an attacker requires authenticated access to the targeted system. Authe
Cisco
Multiple Vulnerabilities in Cisco Unified Communications Manager
vendor_cisco·2013-07-17·CVSS 6.8
CVE-2013-3402 [MEDIUM] CWE-20 Multiple Vulnerabilities in Cisco Unified Communications Manager
Multiple Vulnerabilities in Cisco Unified Communications Manager
Cisco Unified Communications Manager (Unified CM) contains multiple vulnerabilities that could be used together to allow an unauthenticated, remote attacker to gather user credentials, escalate privileges, and execute commands to gain full control of the vulnerable system. A successful attack could allow an unauthenticated attacker to access, create or modify information in Cisco Unified CM.
On June 6, 2013, a French security firm, Lexfo, delivered a public presentation on VoIP security that included a demonstration of multiple vulnerabilities used to compromise Cisco Unified CM. During the presentation, the researchers demonstrated a multistaged attack that chained a number of vulnerabilities, which resulted in a complete
Cisco
Multiple Vulnerabilities in Cisco Unified Communications Manager
vendor_cisco
CVE-2013-3412 Multiple Vulnerabilities in Cisco Unified Communications Manager
CVE-2013-3412: Multiple Vulnerabilities in Cisco Unified Communications Manager
Cisco Unified Communications Manager (Unified CM) contains multiple vulnerabilities that could be used together to allow an unauthenticated, remote attacker to gather user credentials, escalate privileges, and execute commands to gain full control of the vulnerable system. A successful attack could allow an unauthenticated attacker to access, create or modify information in Cisco Unified CM. On June 6, 2013, a French security firm, Lexfo, delivered a public presentation on VoIP security that included a demonstration of multiple vulnerabilities used to compromise Cisco Unified CM. During the presentation, the researchers demonstrated a multistaged attack that chained a number of vulnerabilities, which resulted i
GHSA
GHSA-wjjp-54j2-qxm6: SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7
ghsa_unreviewed·2022-05-17
CVE-2013-3412 [MEDIUM] CWE-89 GHSA-wjjp-54j2-qxm6: SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7
SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuh81766.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-07-18
Published