Opera Remote Location Object Cross-Domain Scripting Vulnerability
BID:10873
Info
Opera Remote Location Object Cross-Domain Scripting Vulnerability
| Bugtraq ID: | 10873 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2004 12:00AM |
| Updated: | Aug 05 2004 12:00AM |
| Credit: | Discovery of this issue is credited to GreyMagic Software. |
| Vulnerable: |
Opera Software Opera Web Browser 7.53 Opera Software Opera Web Browser 7.52 |
| Not Vulnerable: |
Opera Software Opera Web Browser 7.54 |
Discussion
Opera Remote Location Object Cross-Domain Scripting Vulnerability
Opera is affected by a remote location object cross-domain scripting vulnerability. This issue is due to a failure to properly validate methods that a user can access.
An attacker might leverage this issue to steal cookie based authentication credentials, conduct phishing attacks along with other attacks. Furthermore, provided there is an HTML script invoking 'location' methods local to a victim's computer (such as c:/winnt/help/ciadmin.htm in most Microsoft Windows implementations) an attacker can exploit this issue to gain read access to directory contents, files and email read using Opera's email utilities.
Although this issue is reported to affect versions 1.52 and 1.53 of the affected software, it is likely that earlier versions are also affected.
Opera is affected by a remote location object cross-domain scripting vulnerability. This issue is due to a failure to properly validate methods that a user can access.
An attacker might leverage this issue to steal cookie based authentication credentials, conduct phishing attacks along with other attacks. Furthermore, provided there is an HTML script invoking 'location' methods local to a victim's computer (such as c:/winnt/help/ciadmin.htm in most Microsoft Windows implementations) an attacker can exploit this issue to gain read access to directory contents, files and email read using Opera's email utilities.
Although this issue is reported to affect versions 1.52 and 1.53 of the affected software, it is likely that earlier versions are also affected.
Exploit / POC
Opera Remote Location Object Cross-Domain Scripting Vulnerability
GreyMagic has provided two proof of concept exploits that are viewable from their advisory page. Please see the referenced advisory for more information.
GreyMagic has provided two proof of concept exploits that are viewable from their advisory page. Please see the referenced advisory for more information.
Solution / Fix
Opera Remote Location Object Cross-Domain Scripting Vulnerability
Solution:
Gentoo has released advisory GLSA 200408-05 dealing with this issue. All Opera users should upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-www/opera-7.54"
# emerge ">=net-www/opera-7.54"
Please see the referenced Gentoo advisory for more information.
The vendor has released an upgrade dealing with this issue.
Opera Software Opera Web Browser 7.52
Opera Software Opera Web Browser 7.53
Solution:
Gentoo has released advisory GLSA 200408-05 dealing with this issue. All Opera users should upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-www/opera-7.54"
# emerge ">=net-www/opera-7.54"
Please see the referenced Gentoo advisory for more information.
The vendor has released an upgrade dealing with this issue.
Opera Software Opera Web Browser 7.52
-
Opera Software Opera 7.54
http://www.opera.com/download/
Opera Software Opera Web Browser 7.53
-
Opera Software Opera 7.54
http://www.opera.com/download/
References
Opera Remote Location Object Cross-Domain Scripting Vulnerability
References:
References:
- Opera Web Browser Home Page (Opera Software)
- Opera: Location, Location, Location (GreyMagic Software
)