CVE-2011-0960

Cisco Unified Operations Manager < 8.5 - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to execute arbitrary SQL commands via (1) the CCMs parameter to iptm/PRTestCreation.do or (2) the ccm parameter to iptm/TelePresenceReportAction.do, aka Bug ID CSCtn61716.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Sense of Security · textremotewindows
https://www.exploit-db.com/exploits/17304

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/47898
Exploit, URL Repurposed x_refsource_misc
http://www.senseofsecurity.com.au/advisories/SOS-11-006.pdf
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/17304
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/67522

Scores

EPSS 0.0030
EPSS Percentile 53.1%

Details

CWE
CWE-89
Status published
Products (10)
cisco/unified_operations_manager 1.1
cisco/unified_operations_manager 2.0
cisco/unified_operations_manager 2.0.1
cisco/unified_operations_manager 2.0.2
cisco/unified_operations_manager 2.0.3
cisco/unified_operations_manager 2.1
cisco/unified_operations_manager 2.2
cisco/unified_operations_manager 2.3
cisco/unified_operations_manager 8.0
cisco/unified_operations_manager < 8.5
Published May 20, 2011
Tracked Since Feb 18, 2026