CVE-2015-0684
published 2015-04-03CVE-2015-0684: SQL injection vulnerability in the Image Management component in Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to…
PriorityP338medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.36%
68.5th percentile
SQL injection vulnerability in the Image Management component in Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq52515.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_domain_manager | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Domain Manager Application Software SQL Injection Vulnerability
vendor_cisco·2015-03-31·CVSS 6.5
CVE-2015-0684 [MEDIUM] CWE-89 Cisco Unified Communications Domain Manager Application Software SQL Injection Vulnerability
Cisco Unified Communications Domain Manager Application Software SQL Injection Vulnerability
A vulnerability in the Image Management functionality of Cisco Unified Communications Domain Manager Application Software could allow an authenticated, remote attacker to conduct SQL injection attacks.
The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker who could successfully authenticate to a targeted system could exploit this vulnerability by submitting crafted input to be processed by the system. A successful exploit could give the attacker the ability to access sensitive information stored in the database on an affected device, which could be used to conduct further attacks.
Cisco has confirmed the vulnerability and released softwa
GHSA
GHSA-c277-mcfm-qqq5: SQL injection vulnerability in the Image Management component in Cisco Unified Communications Domain Manager 8
ghsa_unreviewed·2022-05-17
CVE-2015-0684 [MEDIUM] CWE-89 GHSA-c277-mcfm-qqq5: SQL injection vulnerability in the Image Management component in Cisco Unified Communications Domain Manager 8
SQL injection vulnerability in the Image Management component in Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq52515.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-04-03
Published