CVE-2016-1393

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
12/05/2016
Last modified:
28/11/2016

Description

SQL injection vulnerability in Cisco Cloud Network Automation Provisioner (CNAP) 1.0 and 1.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy72175.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:cloud_network_automation_provisioner:1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cloud_network_automation_provisioner:1.1:*:*:*:*:*:*:*