← Back

CVE-2012-1417

nvd nist
Published: Sep 17, 2014Modified: May 6, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.

Affected (14)

14 products
Gigabit Color Ip Phone Sip T32g
Gigabit Color Ip Phone Sip T38g
Ip Phone Sip T19p
Ip Phone Sip T20p
Ip Phone Sip T21p
Ip Phone Sip T22p
Ip Phone Sip T26p
Ip Phone Sip T28p
Ip Video Phone Vp530
Ultra Elegant Ip Phone Sip T41p
Ultra Elegant Ip Phone Sip T42g
Ultra Elegant Ip Phone Sip T46g
Ultra Elegant Ip Phone Sip T48g
W52p
Configuration A
14 vulnerable

References (14)

Source: cve@mitre.org
Exploit
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.