Cisco Prime Collaboration Deployment SQL Injection Vulnerability
Description
(:An SQL injection vulnerability has been identified in the interface of the Cisco Prime Collaboration Deployment SQL database.:A remote attacker could exploit it by sending crafted URLs that contain specially crafted SQL statements in order to determine the presence of certain values in the database.::The vulnerability is due to a lack of input validation for user-supplied input in SQL queries.::Cisco announces that a private exploitation code exists.)