Back

CVE-2006-0367

Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a "crafted URL on the CCMAdmin web page."

Published: Jan 22, 2006 Modified: Jun 16, 2026
NVD-CWE-noinfo

CVSS Metrics

Affected Products (18)

Vendor Product Version
cisco call_manager 1.0
cisco call_manager 2.0
cisco call_manager 3.0
cisco call_manager 3.1
cisco call_manager 3.1\(2\)
cisco call_manager 3.1\(3a\)
cisco call_manager 3.2
cisco call_manager 3.3
cisco call_manager 3.3\(3\)
cisco call_manager 3.3\(3\)es61
cisco call_manager 3.3\(4\)es25
cisco call_manager 3.3\(5\)
cisco call_manager 4.0
cisco call_manager 4.0\(2a\)es40
cisco call_manager 4.0\(2a\)sr2b
cisco call_manager 4.1\(2\)es33
cisco call_manager 4.1\(3\)es07
cisco call_manager 4.1\(3\)sr1

GitHub Security Advisory GHSA-frmh-p5vf-w2c9

Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before...

Risk Scores

CVSS Score 6.5 / 10
EPSS Score 2.17%

Top 19% most likely to be exploited

Threat Score 26.7 / 100

Data Sources

NVD EPSS GitHub