CVE-2006-6970 Information

Description

Opera 9.10 Final allows remote attackers to bypass the Fraud Protection mechanism by adding certain characters to the end of a domain name as demonstrated by the .\ and /\ characters which is not caught by the blacklist filter.

Reference

http://kaneda.bohater.net/security/20061220-opera_9.10_final_bypass_fraud_protection.php http://osvdb.org/34927 http://www.securityfocus.com/archive/1/459265/100/0/threaded

Share on: