Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.
| Software | From | Fixed in |
|---|---|---|
| sage / sage | - | - |
| sage / sage | 1.3.6 | 1.3.6.x |
| mozilla / firefox | - | - |
| sage / sage | - | 1.3.9.x |
| sage / sage | 1.0_beta_3 | 1.0_beta_3.x |