CVE-2011-1610
03.05.2011, 22:55
Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or (3) n parameter, aka Bug ID CSCtj42064.
| Vendor | Product | Version |
|---|---|---|
| cisco | unified_communications_manager | 6.0 |
| cisco | unified_communications_manager | 6.1\(1\) |
| cisco | unified_communications_manager | 6.1\(1a\) |
| cisco | unified_communications_manager | 6.1\(1b\) |
| cisco | unified_communications_manager | 6.1\(2\) |
| cisco | unified_communications_manager | 6.1\(2\)su1 |
| cisco | unified_communications_manager | 6.1\(2\)su1a |
| cisco | unified_communications_manager | 6.1\(3\) |
| cisco | unified_communications_manager | 6.1\(3a\) |
| cisco | unified_communications_manager | 6.1\(3b\) |
| cisco | unified_communications_manager | 6.1\(3b\)su1 |
| cisco | unified_communications_manager | 6.1\(4\) |
| cisco | unified_communications_manager | 6.1\(4\)su1 |
| cisco | unified_communications_manager | 6.1\(4a\) |
| cisco | unified_communications_manager | 6.1\(4a\)su2 |
| cisco | unified_communications_manager | 6.1\(5\) |
| cisco | unified_communications_manager | 6.1\(5\)su1 |
| cisco | unified_communications_manager | 6.1\(5\)su2 |
| cisco | unified_communications_manager | 7.0\(1\)su1 |
| cisco | unified_communications_manager | 7.0\(1\)su1a |
| cisco | unified_communications_manager | 7.0\(2\) |
| cisco | unified_communications_manager | 7.0\(2a\) |
| cisco | unified_communications_manager | 7.0\(2a\)su1 |
| cisco | unified_communications_manager | 7.0\(2a\)su2 |
| cisco | unified_communications_manager | 7.1\(2a\) |
| cisco | unified_communications_manager | 7.1\(2a\)su1 |
| cisco | unified_communications_manager | 7.1\(2b\) |
| cisco | unified_communications_manager | 7.1\(2b\)su1 |
| cisco | unified_communications_manager | 7.1\(3\) |
| cisco | unified_communications_manager | 7.1\(3a\) |
| cisco | unified_communications_manager | 7.1\(3a\)su1 |
| cisco | unified_communications_manager | 7.1\(3a\)su1a |
| cisco | unified_communications_manager | 7.1\(3b\) |
| cisco | unified_communications_manager | 7.1\(3b\)su1 |
| cisco | unified_communications_manager | 7.1\(3b\)su2 |
| cisco | unified_communications_manager | 7.1\(5\) |
| cisco | unified_communications_manager | 7.1\(5\)su1 |
| cisco | unified_communications_manager | 7.1\(5\)su1a |
| cisco | unified_communications_manager | 7.1\(5a\) |
| cisco | unified_communications_manager | 7.1\(5b\) |
| cisco | unified_communications_manager | 7.1\(5b\)su2 |
| cisco | unified_communications_manager | 7.1\(5b\)su3 |
| cisco | unified_communications_manager | 8.0 |
| cisco | unified_communications_manager | 8.0\(2c\) |
| cisco | unified_communications_manager | 8.0\(2c\)su1 |
| cisco | unified_communications_manager | 8.0\(3\) |
| cisco | unified_communications_manager | 8.0\(3a\) |
| cisco | unified_communications_manager | 8.0\(3a\)su1 |
𝑥
= Vulnerable software versions
References