The Cisco Unified CallManager is vulnerable to multiple SQL injections in the user interface as well as in the administration interface.

http://www.securiteam.com/securitynews/5PP0M1PNFO.html