Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Yealink
Subscribe
|
Gigabit Color Ip Phone Sip-t32g
Subscribe
Gigabit Color Ip Phone Sip-t38g
Subscribe
Ip Phone Sip-t19p
Subscribe
Ip Phone Sip-t20p
Subscribe
Ip Phone Sip-t21p
Subscribe
Ip Phone Sip-t22p
Subscribe
Ip Phone Sip-t26p
Subscribe
Ip Phone Sip-t28p
Subscribe
Ip Video Phone Vp530
Subscribe
Ultra-elegant Ip Phone Sip-t41p
Subscribe
Ultra-elegant Ip Phone Sip-t42g
Subscribe
Ultra-elegant Ip Phone Sip-t46g
Subscribe
Ultra-elegant Ip Phone Sip-t48g
Subscribe
W52p
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2012-1442 | Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T18:53:37.452Z
Reserved: 2012-02-28T00:00:00.000Z
Link: CVE-2012-1417
No data.
Status : Deferred
Published: 2014-09-17T14:55:02.963
Modified: 2025-04-12T10:46:40.837
Link: CVE-2012-1417
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD