CVE-2006-4711

Publication date 12 September 2006

Last updated 17 July 2025


Ubuntu priority

Description

Multiple cross-site scripting (XSS) vulnerabilities in Sage allow remote attackers to inject arbitrary web script or HTML via an Atom 1.0 feed, as demonstrated by certain test cases of the James M. Snell Atom 1.0 feed reader test suite.

Status

Package Ubuntu Release Status
firefox-sage 7.04 feisty
Fixed 1.3.6-4
6.10 edgy Not in release
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities