1 results (0.006 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 3

Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 5.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Language parameter to Pages/login.aspx, (2) HeaderWarning parameter to Troubleshooting/DiagnosticReport.asp, or (3) User-Agent header to troubleshooting/speedtest.asp. Múltiples vulnerabilidades de ejecución de secuencias de comando en sitios cruzados (XSS) en Kodak InSite v5.5.2 permite a atacantes remotos ejecutar secuencias de comando web o HTML a través de (1) el parámetro Language de Pages/login.aspx, (2) el parámetro HeaderWarning de Troubleshooting/DiagnosticReport.asp, o (3) la cabecera User-Agent a troubleshooting/speedtest.asp. • https://www.exploit-db.com/exploits/35411 https://www.exploit-db.com/exploits/35412 http://securityreason.com/securityalert/8135 http://www.securityfocus.com/archive/1/516880/100/0/threaded http://www.securityfocus.com/archive/1/516881/100/0/threaded http://www.securityfocus.com/bid/46762 https://exchange.xforce.ibmcloud.com/vulnerabilities/65941 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •