Opera Web Browser Download Dialog Manipulation File Execution Vulnerability
BID:15835
Info
Opera Web Browser Download Dialog Manipulation File Execution Vulnerability
| Bugtraq ID: | 15835 |
| Class: | Design Error |
| CVE: |
CVE-2005-2407 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2005 12:00AM |
| Updated: | Jul 12 2009 05:56PM |
| Credit: | Discovered by Jakob Balle, Secunia Research. |
| Vulnerable: |
Opera Software Opera Web Browser 8.0 1 |
| Not Vulnerable: |
Opera Software Opera Web Browser 8.51 Opera Software Opera Web Browser 8.50 Opera Software Opera Web Browser 8.0 2 |
Discussion
Opera Web Browser Download Dialog Manipulation File Execution Vulnerability
Opera Web Browser is prone to a remote code execution vulnerability through manipulation of dialog boxes.
An attacker can hide a 'File Download' dialog box underneath a new browser window and entice a user into double clicking a specific area in the window.
This may result in the execution of arbitrary files.
Opera Web Browser is prone to a remote code execution vulnerability through manipulation of dialog boxes.
An attacker can hide a 'File Download' dialog box underneath a new browser window and entice a user into double clicking a specific area in the window.
This may result in the execution of arbitrary files.
Exploit / POC
Opera Web Browser Download Dialog Manipulation File Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Opera Web Browser Download Dialog Manipulation File Execution Vulnerability
Solution:
Opera 8.02 and subsequent versions are not vulnerable to this issue.
Solution:
Opera 8.02 and subsequent versions are not vulnerable to this issue.
References
Opera Web Browser Download Dialog Manipulation File Execution Vulnerability
References:
References: