Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript to read arbitrary files from the client's local filesystem or display a false URL to the user.
                
            References
                    | Link | Resource | 
|---|---|
| http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0131.html | Broken Link | 
| http://www.greymagic.com/security/advisories/gm008-op/ | Broken Link Exploit Vendor Advisory | 
| http://www.opera.com/docs/changelogs/windows/754/ | Broken Link Patch | 
| http://www.gentoo.org/security/en/glsa/glsa-200408-05.xml | Patch Third Party Advisory | 
| http://www.securityfocus.com/bid/10873 | Broken Link Patch Third Party Advisory VDB Entry | 
| http://osvdb.org/8331 | Broken Link | 
| http://secunia.com/advisories/12233 | Broken Link Patch Vendor Advisory | 
| https://exchange.xforce.ibmcloud.com/vulnerabilities/16904 | Third Party Advisory VDB Entry | 
Configurations
                    Information
                Published : 2004-12-30 21:00
Updated : 2022-02-28 10:29
NVD link : CVE-2004-2570
Mitre link : CVE-2004-2570
JSON object : View
CWE
                
                    
                        
                        CWE-74
                        
            Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
                opera
- opera_browser
 


