{"api_version":"1","generated_at":"2026-07-23T12:25:55+00:00","cve":"CVE-2006-4710","urls":{"html":"https://cve.report/CVE-2006-4710","api":"https://cve.report/api/cve/CVE-2006-4710.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-4710","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-4710"},"summary":{"title":"CVE-2006-4710","description":"Multiple cross-site scripting (XSS) vulnerabilities in NewsGator FeedDemon before 2.0.0.25 allow remote attackers to inject arbitrary web script or HTML via an Atom 1.0 feed, as demonstrated by certain test cases of the James M. Snell Atom 1.0 feed reader test suite.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-09-12 16:07:00","updated_at":"2017-07-20 01:33:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29047","name":"feeddemon-atom-feed-xss(29047)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.cgisecurity.com/papers/RSS-Security.ppt","name":"http://www.cgisecurity.com/papers/RSS-Security.ppt","refsource":"MISC","tags":[],"title":"Access denied | www.cgisecurity.com used Cloudflare to restrict access","mime":"application/vnd.ms-powerpoint","httpstatus":"403","archivestatus":"200"},{"url":"http://www.snellspace.com/wp/?p=448","name":"http://www.snellspace.com/wp/?p=448","refsource":"MISC","tags":["Exploit","Patch"],"title":"snellspace.com  » Blog Archive   » Feed Security","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.snellspace.com/wp/?p=426","name":"http://www.snellspace.com/wp/?p=426","refsource":"MISC","tags":[],"title":"snellspace.com  » Blog Archive   » Holes","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/3686","name":"ADV-2006-3686","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://nick.typepad.com/blog/2006/08/ann_feeddemon_2.html","name":"http://nick.typepad.com/blog/2006/08/ann_feeddemon_2.html","refsource":"CONFIRM","tags":["Patch"],"title":"Nick Bradbury: ANN: FeedDemon 2.0.0.25","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"http://nick.typepad.com/blog/2006/08/feed_security_a_1.html","name":"http://nick.typepad.com/blog/2006/08/feed_security_a_1.html","refsource":"CONFIRM","tags":[],"title":"Nick Bradbury: Feed Security and FeedDemon, Part II","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"http://secunia.com/advisories/21995","name":"21995","refsource":"SECUNIA","tags":[],"title":"FeedDemon Atom Feed Script Insertion Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/20114","name":"20114","refsource":"BID","tags":[],"title":"NewsGator FeedDemon Active Script Code-Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-4710","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-4710","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"4710","vulnerable":"1","versionEndIncluding":"2.0.0.24","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"newsgator","cpe5":"feeddemon","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-4710","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in NewsGator FeedDemon before 2.0.0.25 allow remote attackers to inject arbitrary web script or HTML via an Atom 1.0 feed, as demonstrated by certain test cases of the James M. Snell Atom 1.0 feed reader test suite."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://nick.typepad.com/blog/2006/08/feed_security_a_1.html","refsource":"CONFIRM","url":"http://nick.typepad.com/blog/2006/08/feed_security_a_1.html"},{"name":"ADV-2006-3686","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/3686"},{"name":"http://nick.typepad.com/blog/2006/08/ann_feeddemon_2.html","refsource":"CONFIRM","url":"http://nick.typepad.com/blog/2006/08/ann_feeddemon_2.html"},{"name":"http://www.cgisecurity.com/papers/RSS-Security.ppt","refsource":"MISC","url":"http://www.cgisecurity.com/papers/RSS-Security.ppt"},{"name":"feeddemon-atom-feed-xss(29047)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29047"},{"name":"http://www.snellspace.com/wp/?p=426","refsource":"MISC","url":"http://www.snellspace.com/wp/?p=426"},{"name":"21995","refsource":"SECUNIA","url":"http://secunia.com/advisories/21995"},{"name":"http://www.snellspace.com/wp/?p=448","refsource":"MISC","url":"http://www.snellspace.com/wp/?p=448"},{"name":"20114","refsource":"BID","url":"http://www.securityfocus.com/bid/20114"}]}},"nvd":{"publishedDate":"2006-09-12 16:07:00","lastModifiedDate":"2017-07-20 01:33:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:newsgator:feeddemon:*:*:*:*:*:*:*:*","versionEndIncluding":"2.0.0.24","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"4710","Ordinal":"20047","Title":"CVE-2006-4710","CVE":"CVE-2006-4710","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"4710","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in NewsGator FeedDemon before 2.0.0.25 allow remote attackers to inject arbitrary web script or HTML via an Atom 1.0 feed, as demonstrated by certain test cases of the James M. Snell Atom 1.0 feed reader test suite.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"4710","Ordinal":"2","NoteData":"2006-09-12","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"4710","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}