CVE

Id
70632  
CVE No.
CVE-2014-3336  
Status
Candidate  
Description
SQL injection vulnerability in the web framework in Cisco Unity Connection 9.1(2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted request, aka Bug ID CSCuq31016.  
Phase
Assigned (20140507)  
Votes
None (candidate not yet proposed)  
Comments