Opera Web Browser 'in' Operator Cross Domain Information Disclosure Vulnerability
BID:50915
Info
Opera Web Browser 'in' Operator Cross Domain Information Disclosure Vulnerability
| Bugtraq ID: | 50915 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2011 12:00AM |
| Updated: | Dec 06 2011 12:00AM |
| Credit: | David Bloom |
| Vulnerable: |
Opera Software Opera Web Browser 11.52 Opera Software Opera Web Browser 11.51 Opera Software Opera Web Browser 11.50 Opera Software Opera Web Browser 11.11 Opera Software Opera Web Browser 11.10 Opera Software Opera Web Browser 11.01 Opera Software Opera Web Browser 11.00 |
| Not Vulnerable: |
Opera Software Opera Web Browser 11.60 |
Discussion
Opera Web Browser 'in' Operator Cross Domain Information Disclosure Vulnerability
The Opera web browser is prone to a cross-domain information-disclosure vulnerability.
An attacker can exploit this issue to check the existence of variables on other sites.
Versions prior to Opera Web Browser 11.60 are vulnerable.
The Opera web browser is prone to a cross-domain information-disclosure vulnerability.
An attacker can exploit this issue to check the existence of variables on other sites.
Versions prior to Opera Web Browser 11.60 are vulnerable.
Exploit / POC
Opera Web Browser 'in' Operator Cross Domain Information Disclosure Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to visit a crafted site.
An attacker can exploit this issue by enticing an unsuspecting user to visit a crafted site.
Solution / Fix
Opera Web Browser 'in' Operator Cross Domain Information Disclosure Vulnerability
Solution:
Updates are available. Please see the reference for more details.
Solution:
Updates are available. Please see the reference for more details.
References
Opera Web Browser 'in' Operator Cross Domain Information Disclosure Vulnerability
References:
References:
- Opera 11.60 for Windows changelog (Opera Software)
- Opera Homepage (Opera Software)
- JavaScript 'in' operator allows leakage of cross-domain information Severity (Opera Software)