3.5
CVE-2012-1417
- EPSS 1.09%
- Veröffentlicht 17.09.2014 14:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Yealink ≫ Gigabit Color Ip Phone Sip-t32g Version-
Yealink ≫ Gigabit Color Ip Phone Sip-t38g Version-
Yealink ≫ Ip Phone Sip-t19p Version-
Yealink ≫ Ip Phone Sip-t20p Version-
Yealink ≫ Ip Phone Sip-t21p Version-
Yealink ≫ Ip Phone Sip-t22p Version-
Yealink ≫ Ip Phone Sip-t26p Version-
Yealink ≫ Ip Phone Sip-t28p Version-
Yealink ≫ Ip Video Phone Vp530 Version-
Yealink ≫ Ultra-elegant Ip Phone Sip-t41p Version-
Yealink ≫ Ultra-elegant Ip Phone Sip-t42g Version-
Yealink ≫ Ultra-elegant Ip Phone Sip-t46g Version-
Yealink ≫ Ultra-elegant Ip Phone Sip-t48g Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.09% | 0.772 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.