CVE-2015-0715
published 2015-05-07CVE-2015-0715: SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to…
PriorityP340medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.36%
68.5th percentile
SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug IDs CSCut33447 and CSCut33608.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unity_connection | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2j3f-mgwg-2gjh: SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11
ghsa_unreviewed·2022-05-17
CVE-2015-0715 [MEDIUM] CWE-89 GHSA-2j3f-mgwg-2gjh: SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11
SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug IDs CSCut33447 and CSCut33608.
Cisco
Cisco Unified Communications Manager SQL Injection Vulnerability
vendor_cisco·2015-05-05·CVSS 6.5
CVE-2015-0715 [MEDIUM] CWE-89 Cisco Unified Communications Manager SQL Injection Vulnerability
Cisco Unified Communications Manager SQL Injection Vulnerability
A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacker to perform SQL injection attacks.
The vulnerability is due to a failure to properly sanitize user-supplied input passed to the affected application. An attacker could exploit this vulnerability by logging in to the administrative web interface and submitting a crafted response to the affected pages. If successful, the attacker could access sensitive information stored in the database of the targeted device.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must authenticate to the affected application on a targeted device. This access requirement decreases the
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-05-07
Published