Vulnerabilities > CVE-2006-4710 - Unspecified vulnerability in Newsgator Feeddemon
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN newsgator
nessus
Summary
Multiple cross-site scripting (XSS) vulnerabilities in NewsGator FeedDemon before 2.0.0.25 allow remote attackers to inject arbitrary web script or HTML via an Atom 1.0 feed, as demonstrated by certain test cases of the James M. Snell Atom 1.0 feed reader test suite.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Windows |
NASL id | FEEDDEMON_20025.NASL |
description | According to the Windows registry, the version of FeedDemon, an RSS reader for Windows, installed on the remote host is affected by a flaw due to improper sanitization of RSS feeds of Active Script code. An attacker can exploit this issue to inject arbitrary script into the affected application, which can lead to various cross-site scripting attacks. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22414 |
published | 2006-09-20 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22414 |
title | FeedDemon < 2.0.0.25 Atom Feed Active Script Code Execution |
code |
|
References
- http://nick.typepad.com/blog/2006/08/ann_feeddemon_2.html
- http://nick.typepad.com/blog/2006/08/ann_feeddemon_2.html
- http://nick.typepad.com/blog/2006/08/feed_security_a_1.html
- http://nick.typepad.com/blog/2006/08/feed_security_a_1.html
- http://secunia.com/advisories/21995
- http://secunia.com/advisories/21995
- http://www.cgisecurity.com/papers/RSS-Security.ppt
- http://www.cgisecurity.com/papers/RSS-Security.ppt
- http://www.securityfocus.com/bid/20114
- http://www.securityfocus.com/bid/20114
- http://www.snellspace.com/wp/?p=426
- http://www.snellspace.com/wp/?p=426
- http://www.snellspace.com/wp/?p=448
- http://www.snellspace.com/wp/?p=448
- http://www.vupen.com/english/advisories/2006/3686
- http://www.vupen.com/english/advisories/2006/3686
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29047
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29047