CVE-2009-4101

infoRSS 1.1.4.2 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.

Date published : 2009-11-28

https://addons.mozilla.org/en-US/firefox/addons/versions/361#version-1.2.0

http://secunia.com/advisories/37467