CVE-2008-0026
Last modified
CVE-2008-0026 is a vulnerability of currently unknown severity. SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Callmanager | 5.0 |
| Cisco | Unified Callmanager | 5.0\(1\) |
| Cisco | Unified Callmanager | 5.0\(2\) |
| Cisco | Unified Callmanager | 5.0\(3\) |
| Cisco | Unified Callmanager | 5.0\(3a\) |
| Cisco | Unified Callmanager | 5.0\(4\) |
| Cisco | Unified Callmanager | 5.0_4a |
| Cisco | Unified Callmanager | 5.1 |
| Cisco | Unified Callmanager | 6.0 |
| Cisco | Unified Communications Manager | 5.0 |
| Cisco | Unified Communications Manager | 5.0_1 |
| Cisco | Unified Communications Manager | 5.0_2 |
| Cisco | Unified Communications Manager | 5.0_3 |
| Cisco | Unified Communications Manager | 5.0_3a |
| Cisco | Unified Communications Manager | 5.0_4 |
| Cisco | Unified Communications Manager | 5.0_4a |
| Cisco | Unified Communications Manager | 5.0_4a_su1 |
| Cisco | Unified Communications Manager | 6.0 |
| Cisco | Unified Communications Manager | 6.0_1 |
| Cisco | Unified Communications Manager | 6.1 |
References
- http://secunia.com/advisories/28932Vendor Advisory
- http://www.vupen.com/english/advisories/2008/0542Vendor Advisory
- http://secunia.com/advisories/28932Vendor Advisory
- http://www.vupen.com/english/advisories/2008/0542Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-0026?
How severe is CVE-2008-0026?
How do I fix CVE-2008-0026?
Are you affected by CVE-2008-0026?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
