Opera Web Browser Unspecified Cross Site Scripting Vulnerability
BID:48500
Info
Opera Web Browser Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 48500 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2609 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2011 12:00AM |
| Updated: | Apr 13 2015 09:01PM |
| Credit: | Michal Zalewski |
| Vulnerable: |
Opera Software Opera Web Browser 11.11 Opera Software Opera Web Browser 11.01 Opera Software Opera Web Browser 11.00 Opera Software Opera Web Browser 10.63 Opera Software Opera Web Browser 10.62 Opera Software Opera Web Browser 10.61 Opera Software Opera Web Browser 10.60 Beta1 Opera Software Opera Web Browser 10.60 Opera Software Opera Web Browser 10.60 Opera Software Opera Web Browser 10.54 Opera Software Opera Web Browser 10.54 Opera Software Opera Web Browser 10.53 B Opera Software Opera Web Browser 10.53 Opera Software Opera Web Browser 10.52 Opera Software Opera Web Browser 10.51 Opera Software Opera Web Browser 10.50 Beta2 Opera Software Opera Web Browser 10.50 Beta1 Opera Software Opera Web Browser 10.50 Opera Software Opera Web Browser 10.10 Beta1 Opera Software Opera Web Browser 10.10 Opera Software Opera Web Browser 10.1 Opera Software Opera Web Browser 10.01 Opera Software Opera Web Browser 10.00 Beta3 Opera Software Opera Web Browser 10.00 Beta2 Opera Software Opera Web Browser 10.00 Beta1 Opera Software Opera Web Browser 10.00 Opera Software Opera Web Browser 10 |
| Not Vulnerable: |
Opera Software Opera Web Browser 11.50 |
Discussion
Opera Web Browser Unspecified Cross Site Scripting Vulnerability
The Opera web browser is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser in the context of a targeted site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to Opera Web Browser 11.50 are vulnerable.
The Opera web browser is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser in the context of a targeted site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to Opera Web Browser 11.50 are vulnerable.
Exploit / POC
Opera Web Browser Unspecified Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Opera Web Browser Unspecified Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
Opera Web Browser Unspecified Cross Site Scripting Vulnerability
References:
References:
- Opera Homepage (Opera Software)
- Opera 11.50 for Mac changelog (Opera Software)
- Opera 11.50 for UNIX changelog (Opera Software)
- Opera 11.50 for Windows changelog (Opera Software)