Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Internet & Networking > Firefox, Thunderbird & SeaMonkey

Firefox, Thunderbird & SeaMonkey Post your questions about Mozilla based products (Firefox, Thunderbird & SeaMonkey) here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Reply
 
LinkBack Thread Tools
Old 9th February 2007   #1
WindowsBBS Team Member
 
Ramona's Avatar
 
Profile:
Join Date: Dec 2001
Location: Missouri
Posts: 7,501
Computer Experience:
Experienced Learner
Ramona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation Level

My System

Firefox Sage Extension Feed Script Insertion Vulnerability

TITLE:
Firefox Sage Extension Feed Script Insertion Vulnerability
Quote:
SECUNIA ADVISORY ID:
SA24086

VERIFY ADVISORY:
http://secunia.com/advisories/24086/

CRITICAL:
Less critical

IMPACT:
Cross Site Scripting

WHERE:
>From remote

SOFTWARE:
Sage 1.x (extension for Firefox)
http://secunia.com/product/11907/

DESCRIPTION:
Fukumori has reported a vulnerability in the Sage extension for
Firefox, which can be exploited by malicious people to conduct script
insertion attacks.

The vulnerability is caused due to an input validation error in the
processing of certain tags in RSS feeds. This can e.g. be exploited
to insert and execute arbitrary HTML and script code in a local
context by tricking a user into adding a malicious feed and then
viewing its contents.

The vulnerability is reported in version 1.3.9. Prior versions may
also be affected.

SOLUTION:
Update to version 1.3.10.

PROVIDED AND/OR DISCOVERED BY:
Fukumori

ORIGINAL ADVISORY:
http://jvn.jp/jp/JVN%2384430861/index.html

OTHER REFERENCES:
Sage:
http://sage.mozdev.org/blog/archives..._released.html

http://mozdev.org/bugs/show_bug.cgi?id=16320

Ramona is offline   Reply With Quote



Didn't find the information you thought to find?
Check out these Similar Threads
Reply

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
BSOD amongst other things timeoutgang Malware and Virus Removal 21 5th January 2007 23:06
Firefox Sage Extension Feed Script Insertion Vulnerability Ramona Firefox, Thunderbird & SeaMonkey 0 10th November 2006 22:27
Firefox Sage Extension RSS Feed Script Insertion Vulnerability Ramona Firefox, Thunderbird & SeaMonkey 0 11th September 2006 20:55
Firefox Greasemonkey Extension Disclosure of Sensitive Information Ramona Firefox, Thunderbird & SeaMonkey 0 21st July 2005 18:25
error report bobm735 Windows XP 24 23rd October 2004 09:45


All times are GMT +1. The time now is 13:40.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]