CVE-2006-0367
published 2006-01-22CVE-2006-0367: Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote…
PriorityP424medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.12%
79.7th percentile
Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a "crafted URL on the CCMAdmin web page."
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-frmh-p5vf-w2c9: Unspecified vulnerability in Cisco CallManager 3
ghsa_unreviewed·2022-05-01
CVE-2006-0367 [MEDIUM] GHSA-frmh-p5vf-w2c9: Unspecified vulnerability in Cisco CallManager 3
Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a "crafted URL on the CCMAdmin web page."
Cisco
Cisco Call Manager Privilege Escalation
vendor_cisco·2006-01-18
CVE-2006-0367 CWE-264 Cisco Call Manager Privilege Escalation
Cisco Call Manager Privilege Escalation
Cisco CallManager (CCM) is the software-based call-processing component
of the Cisco IP telephony solution which extends enterprise telephony features
and functions to packet telephony network devices such as IP phones, media
processing devices, voice-over-IP (VoIP) gateways, and multimedia applications.
Cisco CallManager versions with Multi Level Administration (MLA) enabled may be
vulnerable to privilege escalations, which may result in read-only users
gaining administrative access.
Cisco has made free software available to address this vulnerability
for affected customers. There are workarounds available to mitigate the effects
of the vulnerability.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurity
Cisco
Cisco Call Manager Privilege Escalation
vendor_cisco
CVE-2006-0367 Cisco Call Manager Privilege Escalation
CVE-2006-0367: Cisco Call Manager Privilege Escalation
Cisco CallManager (CCM) is the software-based call-processing component of the Cisco IP telephony solution which extends enterprise telephony features and functions to packet telephony network devices such as IP phones, media processing devices, voice-over-IP (VoIP) gateways, and multimedia applications. Cisco CallManager versions with Multi Level Administration (MLA) enabled may be vulnerable to privilege escalations, which may result in read-only users gaining administrative access. Cisco has made free software available to address this vulnerability for affected customers. There are
CWE: CWE-264, CWE-264
Bug IDs: CSCef75361, CSCsb12765, CSCsb88649, CSCsc26275
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/18501http://securitytracker.com/id?1015502http://www.cisco.com/warp/public/707/cisco-sa-20060118-ccmpe.shtmlhttp://www.osvdb.org/22621http://www.securityfocus.com/bid/16293http://www.vupen.com/english/advisories/2006/0250https://exchange.xforce.ibmcloud.com/vulnerabilities/24172http://secunia.com/advisories/18501http://securitytracker.com/id?1015502http://www.cisco.com/warp/public/707/cisco-sa-20060118-ccmpe.shtmlhttp://www.osvdb.org/22621http://www.securityfocus.com/bid/16293http://www.vupen.com/english/advisories/2006/0250https://exchange.xforce.ibmcloud.com/vulnerabilities/24172
2006-01-22
Published