CVE-2011-1427
Kodak InSite 5.5.2 - Cross-Site Scripting via Language Parameter, HeaderWarning Parameter, or User-Agent Header
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2011-1427. PoCs published by Dionach.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Kodak InSite 5.5.2 by injecting a script tag into the 'HeaderWarning' parameter of the DiagnosticReport.asp page. The vulnerability allows arbitrary JavaScript execution in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 5.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Language parameter to Pages/login.aspx, (2) HeaderWarning parameter to Troubleshooting/DiagnosticReport.asp, or (3) User-Agent header to troubleshooting/speedtest.asp.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Kodak InSite 5.5.2 by injecting a script tag into the 'HeaderWarning' parameter of the DiagnosticReport.asp page. The vulnerability allows arbitrary JavaScript execution in the context of the affected site.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Kodak InSite 5.5.2 by injecting malicious JavaScript into the 'Language' parameter of the login page URL. The payload triggers an alert dialog, confirming the vulnerability.