Lucene search

K
cveCiscoCVE-2013-5517
HistoryOct 02, 2013 - 10:55 p.m.

CVE-2013-5517

2013-10-0222:55:23
CWE-89
cisco
web.nvd.nist.gov
28
cve-2013-5517
sql injection
cisco
unified communications domain manager
vulnerability
nvd
bug id cscuh96567

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

8.1

Confidence

Low

EPSS

0.002

Percentile

56.3%

SQL injection vulnerability in the web framework in Cisco Unified Communications Domain Manager allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuh96567.

Affected configurations

Nvd
Node
ciscounified_communications_domain_managerMatch-
VendorProductVersionCPE
ciscounified_communications_domain_manager-cpe:2.3:a:cisco:unified_communications_domain_manager:-:*:*:*:*:*:*:*

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

8.1

Confidence

Low

EPSS

0.002

Percentile

56.3%

Related for CVE-2013-5517