Multiple cross-site scripting (XSS) vulnerabilities in NewsGator FeedDemon before 2.0.0.25 allow remote attackers to inject arbitrary web script or HTML via an Atom 1.0 feed, as demonstrated by certain test cases of the James M. Snell Atom 1.0 feed reader test suite.
https://exchange.xforce.ibmcloud.com/vulnerabilities/29047
https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-4697
http://www.vupen.com/english/advisories/2006/3686
http://www.snellspace.com/wp/?p=448
http://www.snellspace.com/wp/?p=426
http://www.securityfocus.com/bid/20114
http://www.cgisecurity.com/papers/RSS-Security.ppt
http://secunia.com/advisories/21995