Sage 1.4.3 and earlier extension for Firefox performs certain operations...
Vulnerability Description
Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-4102
Credits & Attribution
No credits recorded in the NVD database.
References
- http://jvn.jp/en/jp/JVN99203127/index.html
- http://secunia.com/advisories/37466
- http://www.securityfocus.com/bid/37120
- http://forums.mozillazine.org/viewtopic.php?f=48&t=1603515&start=0
- http://www.vupen.com/english/advisories/2009/3324
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54396
- http://jvndb.jvn.jp/jvndb/JVNDB-2011-000070
- http://www.net-security.org/secworld.php?id=8527
- http://www.debian.org/security/2009/dsa-1951
Affected Vendor
sage.mozdev
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.