SQL Injection Vulnerabilities in Cisco Unified Communications Manager and Presence Server
CVE-2014-3339
Currently unrated
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 12 August 2014
Summary
Multiple SQL injection vulnerabilities exist within the administrative web interface of Cisco Unified Communications Manager and Cisco Unified Presence Server. These vulnerabilities allow remote authenticated users to execute arbitrary SQL commands through carefully crafted inputs sent to specific pages of the affected applications. This unauthorized access can compromise the integrity of the database and expose sensitive data, posing significant risks to organizations relying on these communication solutions.
References
Timeline
Vulnerability published
Vulnerability Reserved