CVE Vulnerabilities

CVE-2006-6919

Published: Jan 11, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Firefox Sage extension 1.3.8 and earlier allows remote attackers to execute arbitrary Javascript in the local context via an RSS feed with an img tag containing the script followed by an extra trailing >, which Sage modifies to close the img element before the malicious script.

Affected Software

NameVendorStart VersionEnd Version
SageSage-mozdev*1.3.8 (including)

References