2 results (0.004 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 6.5 to 8.0 allow remote attackers to inject arbitrary web script via the (1) "paramFile" parameter to /Site/Troubleshooting/DiagnosticReport.asp, or (2) "paramFile" parameter to /Site/Troubleshooting/SpeedTest.asp. Múltiples vulnerabilidades de Cross-Site Scripting (XSS) en Kodak InSite entre las versiones 6.5 y 8.0 permiten que atacantes remotos inyecten scripts web arbitrarios mediante el (1) parámetro "paramFile" en /Site/Troubleshooting/DiagnosticReport.asp o el (2) parámetro "paramFile" en /Site/Troubleshooting/SpeedTest.asp. • https://packetstormsecurity.com/files/142587/Kodak-InSite-8.0-Cross-Site-Scripting.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 3

Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 5.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Language parameter to Pages/login.aspx, (2) HeaderWarning parameter to Troubleshooting/DiagnosticReport.asp, or (3) User-Agent header to troubleshooting/speedtest.asp. Múltiples vulnerabilidades de ejecución de secuencias de comando en sitios cruzados (XSS) en Kodak InSite v5.5.2 permite a atacantes remotos ejecutar secuencias de comando web o HTML a través de (1) el parámetro Language de Pages/login.aspx, (2) el parámetro HeaderWarning de Troubleshooting/DiagnosticReport.asp, o (3) la cabecera User-Agent a troubleshooting/speedtest.asp. • https://www.exploit-db.com/exploits/35411 https://www.exploit-db.com/exploits/35412 http://securityreason.com/securityalert/8135 http://www.securityfocus.com/archive/1/516880/100/0/threaded http://www.securityfocus.com/archive/1/516881/100/0/threaded http://www.securityfocus.com/bid/46762 https://exchange.xforce.ibmcloud.com/vulnerabilities/65941 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •