CVE-2008-4795 Information

Description

The links panel in Opera before 9.62 processes Javascript within the context of the \outermost page\ of a frame which allows remote attackers to inject arbitrary web script or HTML via cross-site scripting (XSS) attacks.

Reference

http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00012.html http://secunia.com/advisories/32538 http://security.gentoo.org/glsa/glsa-200811-01.xml http://www.opera.com/support/search/view/907/ http://www.securityfocus.com/bid/31991 http://www.securitytracker.com/id?1021127 https://exchange.xforce.ibmcloud.com/vulnerabilities/46220

Share on: