Unrated severityNVD Advisory· Published Feb 13, 2007· Updated Apr 23, 2026
CVE-2007-0896
CVE-2007-0896
Description
Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.
Affected products
4- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- jvn.jp/jp/JVN%2384430861/index.htmlnvdVendor Advisory
- secunia.com/advisories/24086nvdVendor Advisory
- mozdev.org/bugs/show_bug.cginvd
- osvdb.org/33131nvd
- sage.mozdev.org/blog/archives/2007/1/sage_1_3_10_released.htmlnvd
- www.securityfocus.com/bid/22493nvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/32395nvd
News mentions
0No linked articles in our index yet.