Record summary

CVE-2008-0026 has a selected CVSS score of 6.5; EIP currently links 1 catalogued exploit.

Description

SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBCisco Unified Communications Manager 6.1 - 'key' SQL InjectionExploitDB exploitby Nico LeideckerNot analyzed1 file
ExploitDB

PoC details

References

7