Opera before 11.65 does not ensure that the address field corresponds to the displayed web page during blocked navigation, which makes it easier for remote attackers to conduct spoofing attacks by detecting and preventing attempts to load a different web page.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2012-06-14 12:55
Updated : 2012-06-14 21:00
NVD link : CVE-2012-3560
Mitre link : CVE-2012-3560
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
opera
- opera_browser