CVE-2006-4710
Summary
| CVE | CVE-2006-4710 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-12 16:07:00 UTC |
| Updated | 2017-07-20 01:33:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in NewsGator FeedDemon before 2.0.0.25 allow remote attackers to inject arbitrary web script or HTML via an Atom 1.0 feed, as demonstrated by certain test cases of the James M. Snell Atom 1.0 feed reader test suite. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Access denied | www.cgisecurity.com used Cloudflare to restrict access | MISC | www.cgisecurity.com | |
| snellspace.com » Blog Archive » Feed Security | MISC | www.snellspace.com | Exploit, Patch |
| snellspace.com » Blog Archive » Holes | MISC | www.snellspace.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Nick Bradbury: ANN: FeedDemon 2.0.0.25 | CONFIRM | nick.typepad.com | Patch |
| Nick Bradbury: Feed Security and FeedDemon, Part II | CONFIRM | nick.typepad.com | |
| FeedDemon Atom Feed Script Insertion Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | |
| NewsGator FeedDemon Active Script Code-Execution Vulnerability | BID | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.