SQL Injection Vulnerabilities in Cisco CallManager and Unified Communications Manager
CVE-2007-4634

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
31 August 2007

Summary

Remote attackers can exploit SQL injection vulnerabilities present in the Cisco CallManager and Unified Communications Manager systems. These vulnerabilities arise when input parameters, such as the lang variable used in user and admin logon pages, are not properly sanitized. By manipulating this parameter, an attacker could execute arbitrary SQL commands against the underlying database, potentially leading to unauthorized access to sensitive data, modification of records, or complete system compromise.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.