PT-2006-1438 · Cisco · Cisco Callmanager

Published

2006-01-22

·

Updated

2017-07-20

·

CVE-2006-0367

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cisco CallManager versions 3.2 and earlier Cisco CallManager version 3.3 before 3.3(5)SR1 Cisco CallManager version 4.0 before 4.0(2a)SR2c Cisco CallManager version 4.1 before 4.1(3)SR2
Description The issue allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a crafted URL on the CCMAdmin web page.
Recommendations For Cisco CallManager versions 3.2 and earlier, update to a version later than 3.2. For Cisco CallManager version 3.3, update to 3.3(5)SR1 or later. For Cisco CallManager version 4.0, update to 4.0(2a)SR2c or later. For Cisco CallManager version 4.1, update to 4.1(3)SR2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0367

Affected Products

Cisco Callmanager