CVE-2014-0734
published 2014-02-20CVE-2014-0734: SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and…
PriorityP343high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.21%
64.8th percentile
SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum46483.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | <= 10.0\(1\) | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager CAPF Unauthenticated Blind SQL Injection Vulnerability
vendor_cisco·2014-02-19·CVSS 7.5
CVE-2014-0734 [HIGH] CWE-89 Cisco Unified Communications Manager CAPF Unauthenticated Blind SQL Injection Vulnerability
Cisco Unified Communications Manager CAPF Unauthenticated Blind SQL Injection Vulnerability
A vulnerability in the Certificate Authority Proxy Function (CAPF) of Cisco Unified Communications Manager (Cisco Unified CM) could allow an unauthenticated, remote attacker to impact the integrity of the system by executing arbitrary SQL queries.
The vulnerability is due to a failure to validate user-supplied input
used in SQL queries. An attacker could exploit this vulnerability by
sending crafted URLs that include SQL statements. An exploit could allow
the attacker to determine the presence of certain values in the
database.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit the vulnerability, the attacker may provide a link th
GHSA
GHSA-4c72-3jr9-g459: SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Manager (Unified CM) 10
ghsa_unreviewed·2022-05-17
CVE-2014-0734 [HIGH] CWE-89 GHSA-4c72-3jr9-g459: SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Manager (Unified CM) 10
SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum46483.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0734http://tools.cisco.com/security/center/viewAlert.x?alertId=32916http://www.securityfocus.com/bid/65645http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0734http://tools.cisco.com/security/center/viewAlert.x?alertId=32916http://www.securityfocus.com/bid/65645
2014-02-20
Published