Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Opera Automatic Redirection Cross Site Scripting Vulnerability

A cross site scripting vulnerability has been reported in Opera browsers for Windows and Linux platforms. The vulnerability exists due to insufficient sanitization of some user-supplied input when redirecting visitors to another page or site.

When a user visits a site that redirects a user to another page, attacker-supplied script code will be interpreted by Opera in the security context of the maliciuos site.

Exploitation of this issue may enable an attacker to steal cookie-based authentication credentials of victim users. Other attacks are also possible.

Update (Jun 16, 2005): Reports indicate that this vulnerability was reintroduced in Opera 8.0.







 

Privacy Statement
Copyright 2009, SecurityFocus