CVE-2015-6299
published 2015-09-20CVE-2015-6299: SQL injection vulnerability in the web interface in Cisco Unity Connection 9.1(1.2) and earlier allows remote authenticated users to execute arbitrary SQL…
PriorityP340medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.59%
72.8th percentile
SQL injection vulnerability in the web interface in Cisco Unity Connection 9.1(1.2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted POST request, aka Bug ID CSCuv63824.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unity Connection Web Interface SQL Injection Vulnerability
vendor_cisco·2015-09-18·CVSS 6.5
CVE-2015-6299 [MEDIUM] CWE-89 Cisco Unity Connection Web Interface SQL Injection Vulnerability
Cisco Unity Connection Web Interface SQL Injection Vulnerability
A vulnerability in the web interface of Cisco Unity Connection (UC) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries.
The vulnerability is due to a lack of input validation on user-supplied input in SQL queries. An attacker could exploit this vulnerability by entering a maliciously crafted value containing SQL commands as an HTTP POST request parameter. An exploit could allow the attacker to determine the presence of certain values in the database.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit this vulnerability, an attacker must
authenticate to the targeted device. This access requirement may redu
GHSA
GHSA-4gf4-55f6-hq4x: SQL injection vulnerability in the web interface in Cisco Unity Connection 9
ghsa_unreviewed·2022-05-17
CVE-2015-6299 [MEDIUM] CWE-89 GHSA-4gf4-55f6-hq4x: SQL injection vulnerability in the web interface in Cisco Unity Connection 9
SQL injection vulnerability in the web interface in Cisco Unity Connection 9.1(1.2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted POST request, aka Bug ID CSCuv63824.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-09-20
Published