VID |
28191 |
Severity |
30 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
The Windows host has a version of FeedDemon that is vulnerable to multiple cross-site scripting vulnerabilities. NewsGator FeedDemon is an RSS reader for Microsoft Windows platforms. FeedDemon versions prior to 2.0.0.25 could allow a remote attacker to execute arbitrary Active Script code, caused by multiple cross-site scripting vulnerabilities when processing Atom feeds containing malformed data. These vulnerabilities could be exploited by a remote attacker to cause arbitrary scripting code to be executed by the user's browser.
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://nick.typepad.com/blog/2006/08/feed_security_a_1.html http://nick.typepad.com/blog/2006/08/ann_feeddemon_2.html http://www.frsirt.com/english/advisories/2006/3686 http://secunia.com/advisories/21995/
* Platforms Affected: NewsGator FeedDemon versions prior to 2.0.0.25 Any operating system Any version |
Recommendation |
Upgrade to the latest version of FeedDemon (2.0.0.25 or later), available from the FeedDemon Web site at http://www.newsgator.com/NGOLProduct.aspx?ProdId=FeedDemon |
Related URL |
CVE-2006-4710 (CVE) |
Related URL |
20114 (SecurityFocus) |
Related URL |
29047 (ISS) |
|