Opera before 11.65 does not properly restrict the reading of JSON strings, which allows remote attackers to perform cross-domain loading of JSON resources and consequently obtain sensitive information via a crafted web site.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2012-06-14 12:55
Updated : 2012-06-15 06:45
NVD link : CVE-2012-3557
Mitre link : CVE-2012-3557
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
opera
- opera_browser