CVE-2009-4101 Information

Description

infoRSS 1.1.4.2 and earlier extension for Firefox performs certain operations with chrome privileges which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.

Reference

http://secunia.com/advisories/37467 http://www.vupen.com/english/advisories/2009/3323 https://addons.mozilla.org/en-US/firefox/addons/versions/361version-1.2.0 https://exchange.xforce.ibmcloud.com/vulnerabilities/54370

Share on: