CVE-2010-3039
/usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in a request to the administrative interface, aka Bug IDs CSCti52041 and CSCti74930.
- Affected products
- Cisco Unified Communications Manager
- Cisco Unified Communications Manager
- = 6.0, 6.1\(1\), 6.1\(1a\), 6.1\(1b\), 6.1\(2\), 6.1\(2\)su1, 6.1\(2\)su1a, 6.1\(3\), 6.1\(3a\), 6.1\(3b\), 6.1\(3b\)su1, 6.1\(4\), 6.1\(4\)su1, 6.1\(4a\), 6.1\(4a\)su2, 6.1\(5\)
- Fix
- Available
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 8.6% (95th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2010-11-09
CVE-2010-3039 at NVD
2 known exploits for CVE-2010-3039
Proof-of-concept code and exploit modules indexed by Sploitus