mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-06-19 17:32:41 +00:00
102 lines
3.7 KiB
JSON
102 lines
3.7 KiB
JSON
{
|
|
"CVE_data_meta": {
|
|
"ASSIGNER": "psirt@cisco.com",
|
|
"ID": "CVE-2011-1610",
|
|
"STATE": "PUBLIC"
|
|
},
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "n/a",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "n/a"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"vendor_name": "n/a"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"data_format": "MITRE",
|
|
"data_type": "CVE",
|
|
"data_version": "4.0",
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or (3) n parameter, aka Bug ID CSCtj42064."
|
|
}
|
|
]
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "n/a"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"name": "http://zerodayinitiative.com/advisories/ZDI-11-143/",
|
|
"refsource": "MISC",
|
|
"url": "http://zerodayinitiative.com/advisories/ZDI-11-143/"
|
|
},
|
|
{
|
|
"name": "44331",
|
|
"refsource": "SECUNIA",
|
|
"url": "http://secunia.com/advisories/44331"
|
|
},
|
|
{
|
|
"name": "20110428 ZDI-11-143: Cisco Unified CallManager xmldirectorylist.jsp SQL Injection Vulnerability",
|
|
"refsource": "BUGTRAQ",
|
|
"url": "http://www.securityfocus.com/archive/1/517727/100/0/threaded"
|
|
},
|
|
{
|
|
"name": "20110502 Re: ZDI-11-143: Cisco Unified CallManager xmldirectorylist.jsp SQL Injection Vulnerability",
|
|
"refsource": "FULLDISC",
|
|
"url": "http://archives.neohapsis.com/archives/fulldisclosure/2011-05/0051.html"
|
|
},
|
|
{
|
|
"name": "1025449",
|
|
"refsource": "SECTRACK",
|
|
"url": "http://www.securitytracker.com/id?1025449"
|
|
},
|
|
{
|
|
"name": "ADV-2011-1122",
|
|
"refsource": "VUPEN",
|
|
"url": "http://www.vupen.com/english/advisories/2011/1122"
|
|
},
|
|
{
|
|
"name": "ucm-sql-injection(67126)",
|
|
"refsource": "XF",
|
|
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67126"
|
|
},
|
|
{
|
|
"name": "20110427 Multiple Vulnerabilities in Cisco Unified Communications Manager",
|
|
"refsource": "CISCO",
|
|
"url": "http://www.cisco.com/en/US/products/products_security_advisory09186a0080b79904.shtml"
|
|
},
|
|
{
|
|
"name": "47607",
|
|
"refsource": "BID",
|
|
"url": "http://www.securityfocus.com/bid/47607"
|
|
}
|
|
]
|
|
}
|
|
} |