CVE-2014-3428
16.06.2014, 18:55
Cross-site scripting (XSS) vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary web script or HTML via the model parameter to servlet.
Vendor | Product | Version |
---|---|---|
yealink | voip_phone_firmware | 28.72.0.2 |
yealink | voip_phone | 28.2.0.128.0.0.0 |
𝑥
= Vulnerable software versions
References