PT-2011-3253 · Apache+1 · Apache Http Server+1

Ven Taute

·

Published

2011-04-28

·

Updated

2018-10-09

·

CVE-2011-1610

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Unified Communications Manager versions 6.x through 6.1(5)su2, 7.x through 7.1(5)su3, 8.0 through 8.0(3a)su1, and 8.5 through 8.5(0)su0
Description The issue allows remote attackers to execute arbitrary SQL commands via the f, l, or n parameter in the xmldirectorylist.jsp file of the embedded Apache HTTP Server component.
Recommendations For versions 6.x through 6.1(5)su2, update to version 6.1(5)su3 or later. For versions 7.x through 7.1(5)su3, update to version 7.1(5)su4 or later. For versions 8.0 through 8.0(3a)su1, update to version 8.0(3a)su2 or later. For versions 8.5 through 8.5(0)su0, update to version 8.5(1)su1 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1610
ZDI-11-143

Affected Products

Apache Http Server
Cisco Unified Communications Manager