Security Advisory
CVE-2014-0727
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
SQL injection vulnerability in the CallManager Interactive Voice Response (CMIVR) interface in Cisco Unified Communications Manager (UCM) allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum05318.