|
|
| |
|
| |
Opera: Multiple spoofing vulnerabilities
| Package(s): | opera |
CVE #(s): | |
| Created: | July 20, 2004 |
Updated: | July 21, 2004 |
| Description: |
Opera fails to remove illegal characters from an URI of a link and to check
that the target frame of a link belongs to the same website as the
link. Opera also updates the address bar before loading a page.
Additionally, Opera contains a certificate verification problem.
These vulnerabilities could allow an attacker to impersonate legitimate
websites to steal sensitive information from users. This could be done by
obfuscating the real URI of a link or by injecting a malicious frame into
an arbitrary frame of another browser window. |
| Alerts: |
|
( Log in to post comments)
|
|
|