6.8
CVSSv2

CVE-2006-6919

Published: 11/01/2007 Updated: 16/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Firefox Sage extension 1.3.8 and previous versions allows remote malicious users to execute arbitrary Javascript in the local context via an RSS feed with an img tag containing the script followed by an extra trailing ">", which Sage modifies to close the img element before the malicious script.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sage-mozdev sage

Exploits

source: wwwsecurityfocuscom/bid/19928/info The application is prone to an input-validation vulnerability that allows malicious HTML and script code to be injected before it is used in dynamically generated content Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacke ...