CVE-2009-4101
29.11.2009, 13:08
infoRSS 1.1.4.2 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.Enginsight
Vendor | Product | Version |
---|---|---|
didier_ernotte | inforss | 𝑥 ≤ 1.1.4.2 |
didier_ernotte | inforss | 0.5 |
didier_ernotte | inforss | 0.7.7 |
didier_ernotte | inforss | 0.8.4 |
didier_ernotte | inforss | 0.8.7 |
didier_ernotte | inforss | 0.8.8.1 |
didier_ernotte | inforss | 0.8.8.2 |
didier_ernotte | inforss | 0.8.9 |
didier_ernotte | inforss | 0.8.9.1 |
didier_ernotte | inforss | 0.8.9.3 |
didier_ernotte | inforss | 0.8.9.4 |
didier_ernotte | inforss | 0.8.9.5 |
didier_ernotte | inforss | 0.9.0 |
didier_ernotte | inforss | 0.10.0 |
didier_ernotte | inforss | 0.10.1 |
didier_ernotte | inforss | 1.0.0 |
didier_ernotte | inforss | 1.1.0.1 |
didier_ernotte | inforss | 1.1.1 |
didier_ernotte | inforss | 1.1.2 |
didier_ernotte | inforss | 1.1.3 |
didier_ernotte | inforss | 1.1.4 |
didier_ernotte | inforss | 1.1.4.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References