4.3
CVE-2006-4710
- EPSS 1.67%
- Veröffentlicht 12.09.2006 16:07:00
- Zuletzt bearbeitet 16.06.2026 22:29:37
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in NewsGator FeedDemon before 2.0.0.25 allow remote attackers to inject arbitrary web script or HTML via an Atom 1.0 feed, as demonstrated by certain test cases of the James M. Snell Atom 1.0 feed reader test suite.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.67% | 0.737 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://nick.typepad.com/blog/2006/08/ann_feeddemon_2.html
http://nick.typepad.com/blog/2006/08/feed_security_a_1.html
http://secunia.com/advisories/21995
http://www.cgisecurity.com/papers/RSS-Security.ppt
http://www.securityfocus.com/bid/20114
http://www.snellspace.com/wp/?p=426
http://www.snellspace.com/wp/?p=448
http://www.vupen.com/english/advisories/2006/3686
https://exchange.xforce.ibmcloud.com/vulnerabilities/29047