Opera Web Browser XMLHttpRequest Object Cross-Domain Access Vulnerability
BID:13970
Info
Opera Web Browser XMLHttpRequest Object Cross-Domain Access Vulnerability
| Bugtraq ID: | 13970 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-1475 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2005 12:00AM |
| Updated: | Mar 06 2007 12:25AM |
| Credit: | Discovery is credited to Jakob Balle, Secunia Research. |
| Vulnerable: |
S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Opera Software Opera Web Browser 8.0 |
| Not Vulnerable: |
Opera Software Opera Web Browser 8.0 1 |
Discussion
Opera Web Browser XMLHttpRequest Object Cross-Domain Access Vulnerability
Opera Web Browser is prone to an issue that allows a violation of the cross-domain security model.
This issue arises due to an access-validation error affecting the 'XMLHttpRequest' object.
Successful exploitation may allow an attacker to steal cookies, manipulate content, obtain sensitive information, or launch other attacks.
Opera Web Browser version 8.0 is prone to this issue.
Opera Web Browser is prone to an issue that allows a violation of the cross-domain security model.
This issue arises due to an access-validation error affecting the 'XMLHttpRequest' object.
Successful exploitation may allow an attacker to steal cookies, manipulate content, obtain sensitive information, or launch other attacks.
Opera Web Browser version 8.0 is prone to this issue.
Exploit / POC
Opera Web Browser XMLHttpRequest Object Cross-Domain Access Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Opera Web Browser XMLHttpRequest Object Cross-Domain Access Vulnerability
Solution:
The vendor has released Opera 8.01 to address this issue.
SUSE has released security announcement SUSE-SA:2005:034 addressing this issue. Please see the referenced advisory for more information.
Opera Software Opera Web Browser 8.0
Solution:
The vendor has released Opera 8.01 to address this issue.
SUSE has released security announcement SUSE-SA:2005:034 addressing this issue. Please see the referenced advisory for more information.
Opera Software Opera Web Browser 8.0
-
Opera Software Opera 8.01
http://www.opera.com/download/
References
Opera Web Browser XMLHttpRequest Object Cross-Domain Access Vulnerability
References:
References:
- Changelog for Opera 8.01 for Windows (Opera Software)
- Opera 8 XMLHttpRequest Security Bypass (Secunia)