CVE Database
/

CVE-2007-0896

Back to search

CVE-2007-0896

Published: Feb 13, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.

VendorProductVersions

n/a

n/a

affected
n/a

References

33131
vdb-entry
x_refsource_OSVDB
1017624
vdb-entry
x_refsource_SECTRACK
JVN#84430861
third-party-advisory
x_refsource_JVN
24086
third-party-advisory
x_refsource_SECUNIA
22493
vdb-entry
x_refsource_BID
sage-rssfeed-xss(32395)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now