CVE-2008-6573
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES) in Avaya Avaya Communication Manager 3.x, 4.0, and 5.0 (1) allow remote attackers to execute arbitrary SQL commands via unspecified vectors related to profiles in the SIP Personal Information Manager (SPIM) in the web interface; and allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to (2) permissions for SPIM profiles in the web interface and (3) a crafted SIP request to the SIP server.
Múltiples vulnerabilidades de inyección SQL en Avaya SIP Enablement Services (SES) en Avaya Avaya Communication Manager 3.x, 4.0, y 5.0 (1) permite a atacantes remotos ejecutar comandos SQL de su elección a través de vectores no especificados relacionados con perfiles en el SIP Personal Information Manager (SPIM) en la interfaz web; y permite a usuarios remotos autenticados ejecutar comandos SQL de su elección a través de vectores no especificados relacionados a (2) permisos para perfiles SPIM en la interfaz web y (3) una petición SIP manipulada en el servidor SIP.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-04-01 CVE Reserved
- 2009-04-01 CVE Published
- 2024-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://osvdb.org/44284 | Vdb Entry | |
http://osvdb.org/44285 | Vdb Entry | |
http://osvdb.org/44286 | Vdb Entry | |
http://support.avaya.com/elmodocs2/security/ASA-2008-150.htm | X_refsource_confirm | |
http://www.securityfocus.com/bid/28682 | Vdb Entry | |
http://www.voipshield.com/research-details.php?id=22 | X_refsource_misc | |
http://www.voipshield.com/research-details.php?id=25 | X_refsource_misc | |
http://www.voipshield.com/research-details.php?id=26 | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41730 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41733 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/29744 | 2017-08-17 | |
http://support.avaya.com/elmodocs2/security/ASA-2008-151.htm | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Avaya Search vendor "Avaya" | Communication Manager Search vendor "Avaya" for product "Communication Manager" | <= 3.1 Search vendor "Avaya" for product "Communication Manager" and version " <= 3.1" | - |
Affected
| ||||||
Avaya Search vendor "Avaya" | Communication Manager Search vendor "Avaya" for product "Communication Manager" | 3.1.1 Search vendor "Avaya" for product "Communication Manager" and version "3.1.1" | - |
Affected
| ||||||
Avaya Search vendor "Avaya" | Communication Manager Search vendor "Avaya" for product "Communication Manager" | 3.1.2 Search vendor "Avaya" for product "Communication Manager" and version "3.1.2" | - |
Affected
| ||||||
Avaya Search vendor "Avaya" | Communication Manager Search vendor "Avaya" for product "Communication Manager" | 3.1.3 Search vendor "Avaya" for product "Communication Manager" and version "3.1.3" | - |
Affected
| ||||||
Avaya Search vendor "Avaya" | Communication Manager Search vendor "Avaya" for product "Communication Manager" | 3.1.4 Search vendor "Avaya" for product "Communication Manager" and version "3.1.4" | - |
Affected
| ||||||
Avaya Search vendor "Avaya" | Communication Manager Search vendor "Avaya" for product "Communication Manager" | 3.1.4 Search vendor "Avaya" for product "Communication Manager" and version "3.1.4" | sp1 |
Affected
| ||||||
Avaya Search vendor "Avaya" | Communication Manager Search vendor "Avaya" for product "Communication Manager" | 3.1.4 Search vendor "Avaya" for product "Communication Manager" and version "3.1.4" | sp2 |
Affected
| ||||||
Avaya Search vendor "Avaya" | Communication Manager Search vendor "Avaya" for product "Communication Manager" | 3.1.5 Search vendor "Avaya" for product "Communication Manager" and version "3.1.5" | - |
Affected
| ||||||
Avaya Search vendor "Avaya" | Communication Manager Search vendor "Avaya" for product "Communication Manager" | 3.1.5 Search vendor "Avaya" for product "Communication Manager" and version "3.1.5" | sp0 |
Affected
| ||||||
Avaya Search vendor "Avaya" | Communication Manager Search vendor "Avaya" for product "Communication Manager" | 4.0 Search vendor "Avaya" for product "Communication Manager" and version "4.0" | - |
Affected
| ||||||
Avaya Search vendor "Avaya" | Communication Manager Search vendor "Avaya" for product "Communication Manager" | 5.0 Search vendor "Avaya" for product "Communication Manager" and version "5.0" | - |
Affected
|