Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript to read arbitrary files from the client's local filesystem or display a false URL to the user.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0131.html | Broken Link |
http://www.greymagic.com/security/advisories/gm008-op/ | Broken Link Exploit Vendor Advisory |
http://www.opera.com/docs/changelogs/windows/754/ | Broken Link Patch |
http://www.gentoo.org/security/en/glsa/glsa-200408-05.xml | Patch Third Party Advisory |
http://www.securityfocus.com/bid/10873 | Broken Link Patch Third Party Advisory VDB Entry |
http://osvdb.org/8331 | Broken Link |
http://secunia.com/advisories/12233 | Broken Link Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16904 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2004-12-30 21:00
Updated : 2022-02-28 10:29
NVD link : CVE-2004-2570
Mitre link : CVE-2004-2570
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
opera
- opera_browser