CVE-2011-0960
Cisco Unified Operations Manager - Multiple Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
Multiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to execute arbitrary SQL commands via (1) the CCMs parameter to iptm/PRTestCreation.do or (2) the ccm parameter to iptm/TelePresenceReportAction.do, aka Bug ID CSCtn61716.
Múltiples vulnerabilidades de inyección SQL en Cisco Unified Operations Manager (CUOM) anterior a v8.6, permite a atacantes remotos ejecuctar comandos SQL de su elección a través de (1) el parámetro CCMs de iptm/PRTestCreation.do o (2) el parámetro ccm de iptm/TelePresenceReportAction.do, también conocido cómo Bug ID CSCtn61716.
Cisco Unified Operations Manager suffers from cross site scripting, remote SQL injection, and directory traversal vulnerabilities. Versions 8.0 and 8.5 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-02-10 CVE Reserved
- 2011-05-18 CVE Published
- 2011-05-18 First Exploit
- 2023-06-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/47898 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/67522 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/17304 | 2011-05-18 | |
http://archives.neohapsis.com/archives/fulldisclosure/2011-05/0371.html | 2024-08-06 | |
http://www.exploit-db.com/exploits/17304 | 2024-08-06 | |
http://www.senseofsecurity.com.au/advisories/SOS-11-006.pdf | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://tools.cisco.com/security/center/viewAlert.x?alertId=23086 | 2024-02-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Unified Operations Manager Search vendor "Cisco" for product "Unified Operations Manager" | <= 8.5 Search vendor "Cisco" for product "Unified Operations Manager" and version " <= 8.5" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Operations Manager Search vendor "Cisco" for product "Unified Operations Manager" | 1.1 Search vendor "Cisco" for product "Unified Operations Manager" and version "1.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Operations Manager Search vendor "Cisco" for product "Unified Operations Manager" | 2.0 Search vendor "Cisco" for product "Unified Operations Manager" and version "2.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Operations Manager Search vendor "Cisco" for product "Unified Operations Manager" | 2.0.1 Search vendor "Cisco" for product "Unified Operations Manager" and version "2.0.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Operations Manager Search vendor "Cisco" for product "Unified Operations Manager" | 2.0.2 Search vendor "Cisco" for product "Unified Operations Manager" and version "2.0.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Operations Manager Search vendor "Cisco" for product "Unified Operations Manager" | 2.0.3 Search vendor "Cisco" for product "Unified Operations Manager" and version "2.0.3" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Operations Manager Search vendor "Cisco" for product "Unified Operations Manager" | 2.1 Search vendor "Cisco" for product "Unified Operations Manager" and version "2.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Operations Manager Search vendor "Cisco" for product "Unified Operations Manager" | 2.2 Search vendor "Cisco" for product "Unified Operations Manager" and version "2.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Operations Manager Search vendor "Cisco" for product "Unified Operations Manager" | 2.3 Search vendor "Cisco" for product "Unified Operations Manager" and version "2.3" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Operations Manager Search vendor "Cisco" for product "Unified Operations Manager" | 8.0 Search vendor "Cisco" for product "Unified Operations Manager" and version "8.0" | - |
Affected
|