← back
CVE-2006-6919

CVE-2006-6919

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 2.2%
from disclosure to weapon0 days
Published on NVDJan 11
1st PoCSep 8
exploitation probability
2.2%top 19% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Firefox Sage extension 1.3.8 and earlier allows remote attackers to execute arbitrary Javascript in the local context via an RSS feed with an img tag containing the script followed by an extra trailing ">", which Sage modifies to close the img element before the malicious script.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.