CVE-2007-0896: XSS
Published Feb 13, 2007
·Updated
Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.
Affected Software
5 affected components
Mozilla Firefox
Sage Sage
Sage Sage<=1.3.9
Sage Sage=1.0_beta_3
Sage Sage=1.3.6
Event History
Feb 13, 2007
CVE Published
11:28 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0896?
CVE-2007-0896 is classified as a Cross-site scripting (XSS) vulnerability with a medium severity level.
2
How do I fix CVE-2007-0896?
To fix CVE-2007-0896, update to Sage version 1.3.10 or later.
3
What types of applications are affected by CVE-2007-0896?
CVE-2007-0896 affects Sage and the Sage++ extensions for Firefox.
4
Can I exploit CVE-2007-0896 via RSS feeds?
Yes, attackers can exploit CVE-2007-0896 by injecting scripts through specially crafted RSS feeds.
5
Is CVE-2007-0896 still a threat today?
CVE-2007-0896 poses a low threat for current systems, but unpatched versions remain vulnerable.