CVE-2006-4712: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Sage 1.3.6 allow remote attackers to inject arbitrary web script or HTML via JavaScript in a content:encoded element within an item element in an RSS feed, as demonstrated by four example content:encoded elements that use XMLHttpRequest to read arbitrary local files, aka "Cross Context Scripting."
Affected Software
Event History
Frequently Asked Questions
What are the risks associated with CVE-2006-4712?
CVE-2006-4712 poses a risk of cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages viewed by users.
How do I fix CVE-2006-4712?
To fix CVE-2006-4712, upgrade Sage to version 1.3.7 or later where the vulnerabilities have been addressed.
What software is affected by CVE-2006-4712?
CVE-2006-4712 specifically affects Sage version 1.3.6.
Can CVE-2006-4712 be exploited remotely?
Yes, CVE-2006-4712 can be exploited remotely by attackers via malformed RSS feeds.
What input vectors are involved in CVE-2006-4712?
CVE-2006-4712 involves cross-site scripting injections through the content:encoded elements in RSS feeds.