Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-0896

Опубликовано: 13 фев. 2007
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefox-sagefixed1.3.10-1package
firefox-sagenot-affectedetchpackage

Примечания

  • http://secunia.com/advisories/24086/

  • might not affect Debian version because HTML mode is disabled. sf: pinged maintainer

EPSS

Процентиль: 92%
0.08996
Низкий

Связанные уязвимости

ubuntu
больше 18 лет назад

Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.

nvd
больше 18 лет назад

Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.

github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.

EPSS

Процентиль: 92%
0.08996
Низкий