SQL Injection Vulnerabilities in Cisco CallManager and Unified Communications Manager
CVE-2007-4634
Currently unrated
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 31 August 2007
Summary
Remote attackers can exploit SQL injection vulnerabilities present in the Cisco CallManager and Unified Communications Manager systems. These vulnerabilities arise when input parameters, such as the lang variable used in user and admin logon pages, are not properly sanitized. By manipulating this parameter, an attacker could execute arbitrary SQL commands against the underlying database, potentially leading to unauthorized access to sensitive data, modification of records, or complete system compromise.
References
Timeline
Vulnerability published
Vulnerability Reserved