Opera Web Browser History Search and Links Panel Cross Site Scripting Vulnerabilities
BID:31991
Info
Opera Web Browser History Search and Links Panel Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 31991 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4795 CVE-2008-4794 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 30 2008 12:00AM |
| Updated: | Nov 04 2008 08:55PM |
| Credit: | Stefano Di Paola and Opera |
| Vulnerable: |
S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 Opera Software Opera Web Browser 9.61 Opera Software Opera Web Browser 9.60 beta 1 Opera Software Opera Web Browser 9.60 Opera Software Opera Web Browser 9.52 Opera Software Opera Web Browser 9.51 Opera Software Opera Web Browser 9.50 beta Opera Software Opera Web Browser 9.5 Opera Software Opera Web Browser 9.27 Opera Software Opera Web Browser 9.26 Opera Software Opera Web Browser 9.25 Opera Software Opera Web Browser 9.24 Opera Software Opera Web Browser 9.23 Opera Software Opera Web Browser 9.22 Opera Software Opera Web Browser 9.21 Opera Software Opera Web Browser 9.20 beta 1 Opera Software Opera Web Browser 9.20 Opera Software Opera Web Browser 9.10 Opera Software Opera Web Browser 9.02 Opera Software Opera Web Browser 9.01 Opera Software Opera Web Browser 9 Gentoo Linux |
| Not Vulnerable: |
Opera Software Opera Web Browser 9.62 |
Discussion
Opera Web Browser History Search and Links Panel Cross Site Scripting Vulnerabilities
Opera Web Browser is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, change the browser's settings, and launch other attacks.
Versions prior to Opera Web Browser 9.62 are vulnerable.
NOTE: The 'History Search' issue described here may be related to the 'History Search' issue that was previously described in BID 31842 'Opera Web Browser Multiple Cross Site Scripting Vulnerabilities'.
Opera Web Browser is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, change the browser's settings, and launch other attacks.
Versions prior to Opera Web Browser 9.62 are vulnerable.
NOTE: The 'History Search' issue described here may be related to the 'History Search' issue that was previously described in BID 31842 'Opera Web Browser Multiple Cross Site Scripting Vulnerabilities'.
Exploit / POC
Opera Web Browser History Search and Links Panel Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
The following exploit code is available:
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
The following exploit code is available:
Solution / Fix
Opera Web Browser History Search and Links Panel Cross Site Scripting Vulnerabilities
Solution:
Opera Web Browser 9.62 addresses these issues. Please see the references for more information.
Solution:
Opera Web Browser 9.62 addresses these issues. Please see the references for more information.
References
Opera Web Browser History Search and Links Panel Cross Site Scripting Vulnerabilities
References:
References:
- A different Opera (Aviv Raff)
- Advisory: History Search can be used to execute arbitrary code (Opera)
- Advisory: The links panel can allow cross-site scripting (Opera)
- Opera Homepage (Opera Software)