CVE-2006-4712

Publication date 12 September 2006

Last updated 24 July 2024


Ubuntu priority

Multiple cross-site scripting (XSS) vulnerabilities in Sage 1.3.6 allow remote attackers to inject arbitrary web script or HTML via JavaScript in a content:encoded element within an item element in an RSS feed, as demonstrated by four example content:encoded elements that use XMLHttpRequest to read arbitrary local files, aka “Cross Context Scripting.”

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
firefox-sage 7.04 feisty
Fixed 1.3.6-4
6.10 edgy Not in release
6.06 LTS dapper Not in release