Korean
<< Back
VID 28191
Severity 30
Port 139,445
Protocol TCP
Class SMB
Detailed Description The Windows host has a version of FeedDemon that is vulnerable to multiple cross-site scripting vulnerabilities. NewsGator FeedDemon is an RSS reader for Microsoft Windows platforms. FeedDemon versions prior to 2.0.0.25 could allow a remote attacker to execute arbitrary Active Script code, caused by multiple cross-site scripting vulnerabilities when processing Atom feeds containing malformed data. These vulnerabilities could be exploited by a remote attacker to cause arbitrary scripting code to be executed by the user's browser.

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://nick.typepad.com/blog/2006/08/feed_security_a_1.html
http://nick.typepad.com/blog/2006/08/ann_feeddemon_2.html
http://www.frsirt.com/english/advisories/2006/3686
http://secunia.com/advisories/21995/

* Platforms Affected:
NewsGator FeedDemon versions prior to 2.0.0.25
Any operating system Any version
Recommendation Upgrade to the latest version of FeedDemon (2.0.0.25 or later), available from the FeedDemon Web site at http://www.newsgator.com/NGOLProduct.aspx?ProdId=FeedDemon
Related URL CVE-2006-4710 (CVE)
Related URL 20114 (SecurityFocus)
Related URL 29047 (ISS)