Opera Web Browser Multiple Cross Site Scripting Vulnerabilities
BID:31842
Info
Opera Web Browser Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 31842 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4697 CVE-2008-4698 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 21 2008 12:00AM |
| Updated: | Nov 04 2008 08:55PM |
| Credit: | David Bloom |
| Vulnerable: |
S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 Opera Software Opera Web Browser 9.60 beta 1 Opera Software Opera Web Browser 9.60 Opera Software Opera Web Browser 9.52 Opera Software Opera Web Browser 9.51 Opera Software Opera Web Browser 9.50 beta Opera Software Opera Web Browser 9.5 Opera Software Opera Web Browser 9.27 Opera Software Opera Web Browser 9.26 Opera Software Opera Web Browser 9.25 Opera Software Opera Web Browser 9.24 Opera Software Opera Web Browser 9.23 Opera Software Opera Web Browser 9.22 Opera Software Opera Web Browser 9.21 Opera Software Opera Web Browser 9.20 beta 1 Opera Software Opera Web Browser 9.20 Opera Software Opera Web Browser 9.10 Opera Software Opera Web Browser 9.02 Opera Software Opera Web Browser 9.01 Opera Software Opera Web Browser 9 Gentoo Linux |
| Not Vulnerable: |
Opera Software Opera Web Browser 9.61 |
Discussion
Opera Web Browser Multiple Cross Site Scripting Vulnerabilities
Opera Web Browser is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Opera Web Browser 9.61 are vulnerable.
NOTE: This BID was previously titled 'Opera Web Browser HTML Injection and Cross Site Scripting Vulnerabilities'. The HTML-injection issue has been given its own record (BID 31869) to better document the issue.
Opera Web Browser is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Opera Web Browser 9.61 are vulnerable.
NOTE: This BID was previously titled 'Opera Web Browser HTML Injection and Cross Site Scripting Vulnerabilities'. The HTML-injection issue has been given its own record (BID 31869) to better document the issue.
Exploit / POC
Opera Web Browser Multiple Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Opera Web Browser Multiple Cross Site Scripting Vulnerabilities
Solution:
Opera 9.61 addresses these issues. Please see the references for more information.
Solution:
Opera 9.61 addresses these issues. Please see the references for more information.
References
Opera Web Browser Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Advisory: Fast Forward can allow cross-site scripting (Opera)
- Advisory: Feed preview can reveal contents of unrelated news feeds (Opera)
- Opera Homepage (Opera Software)