CVE-2014-0726

Cisco Unified Communications Manager < 10.0(1) - SQL Injection via IPMA Interface

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum05326.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/65514
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/103218

Scores

EPSS 0.0126
EPSS Percentile 66.5%

Details

CWE
CWE-89
Status published
Products (2)
cisco/unified_communications_manager 10.0
cisco/unified_communications_manager < 10.0\(1\)
Published Feb 13, 2014
Tracked Since Feb 18, 2026