CVE-2011-1427
Kodak InSite 5.5.2 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 5.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Language parameter to Pages/login.aspx, (2) HeaderWarning parameter to Troubleshooting/DiagnosticReport.asp, or (3) User-Agent header to troubleshooting/speedtest.asp.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Dionach · textwebappsasp
https://www.exploit-db.com/exploits/35412
exploitdb
WORKING POC
VERIFIED
by Dionach · textwebappsasp
https://www.exploit-db.com/exploits/35411
References (5)
Scores
EPSS
0.0075
EPSS Percentile
72.9%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
kodak/insite
n/a/n/a
Timeline
Published
Mar 15, 2011
Tracked Since
Feb 18, 2026