CVE-2017-9085
https://notcve.org/view.php?id=CVE-2017-9085
Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 6.5 to 8.0 allow remote attackers to inject arbitrary web script via the (1) "paramFile" parameter to /Site/Troubleshooting/DiagnosticReport.asp, or (2) "paramFile" parameter to /Site/Troubleshooting/SpeedTest.asp. Múltiples vulnerabilidades de Cross-Site Scripting (XSS) en Kodak InSite entre las versiones 6.5 y 8.0 permiten que atacantes remotos inyecten scripts web arbitrarios mediante el (1) parámetro "paramFile" en /Site/Troubleshooting/DiagnosticReport.asp o el (2) parámetro "paramFile" en /Site/Troubleshooting/SpeedTest.asp. • https://packetstormsecurity.com/files/142587/Kodak-InSite-8.0-Cross-Site-Scripting.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •