VulnerabilityModified
CVE-2012-1417
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.
LOW 3.5EPSS 1.73%
Does this matter?
Lower severity and a low EPSS score (1.73%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
- EPSS
- 1.73% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- yealink/gigabit color ip phone sip-t32g · yealink/gigabit color ip phone sip-t38g · yealink/ip phone sip-t19p · yealink/ip phone sip-t20p · yealink/ip phone sip-t21p · yealink/ip phone sip-t22p · yealink/ip phone sip-t26p · yealink/ip phone sip-t28p · yealink/ip video phone vp530 · yealink/ultra-elegant ip phone sip-t41p · yealink/ultra-elegant ip phone sip-t42g · yealink/ultra-elegant ip phone sip-t46g · yealink/ultra-elegant ip phone sip-t48g · yealink/w52p
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2012-03/0056.html
- http://packetstormsecurity.org/files/110320/yealink-xss.txtExploit
- http://secunia.com/advisories/48194
- http://www.exploit-db.com/exploits/18540Exploit
- http://www.osvdb.org/79675
- http://www.securityfocus.com/bid/52209
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73573
- http://archives.neohapsis.com/archives/bugtraq/2012-03/0056.html
- http://packetstormsecurity.org/files/110320/yealink-xss.txtExploit
- http://secunia.com/advisories/48194
- http://www.exploit-db.com/exploits/18540Exploit
- http://www.osvdb.org/79675
- http://www.securityfocus.com/bid/52209
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73573
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.