Opera Web Browser Prior to 11.61 Information Disclosure and Security Bypass Vulnerabilities
BID:51648
Info
Opera Web Browser Prior to 11.61 Information Disclosure and Security Bypass Vulnerabilities
| Bugtraq ID: | 51648 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 24 2012 12:00AM |
| Updated: | Mar 19 2015 08:09AM |
| Credit: | Vendor and Michal Zalewski |
| Vulnerable: |
Opera Software Opera Web Browser 11.60 Opera Software Opera Web Browser 11.52 Opera Software Opera Web Browser 11.51 Opera Software Opera Web Browser 11.50 Opera Software Opera Web Browser 11.11 Opera Software Opera Web Browser 11.10 Opera Software Opera Web Browser 11.01 Opera Software Opera Web Browser 11.00 Opera Software Opera Web Browser 10.63 Opera Software Opera Web Browser 10.62 Opera Software Opera Web Browser 10.61 Opera Software Opera Web Browser 10.60 Opera Software Opera Web Browser 10.54 Opera Software Opera Web Browser 10.53 Opera Software Opera Web Browser 10.52 Opera Software Opera Web Browser 10.51 Opera Software Opera Web Browser 10.50 |
| Not Vulnerable: |
Opera Software Opera Web Browser 11.61 |
Discussion
Opera Web Browser Prior to 11.61 Information Disclosure and Security Bypass Vulnerabilities
Opera Web Browser is prone to remote information-disclosure and security bypass vulnerabilities.
An attacker may exploit these issues to obtain sensitive information and bypass same-origin policy to execute arbitrary JavaScript in the context of another domain. This may aid in further attacks.
Versions prior to Opera 11.61 are vulnerable.
Opera Web Browser is prone to remote information-disclosure and security bypass vulnerabilities.
An attacker may exploit these issues to obtain sensitive information and bypass same-origin policy to execute arbitrary JavaScript in the context of another domain. This may aid in further attacks.
Versions prior to Opera 11.61 are vulnerable.
Exploit / POC
Opera Web Browser Prior to 11.61 Information Disclosure and Security Bypass Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user into visiting a specially crafted webpage.
Attackers can exploit these issues by enticing an unsuspecting user into visiting a specially crafted webpage.
Solution / Fix
Opera Web Browser Prior to 11.61 Information Disclosure and Security Bypass Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Opera Web Browser Prior to 11.61 Information Disclosure and Security Bypass Vulnerabilities
References:
References:
- Opera 11.61 for Windows changelog (Opera Software)
- Opera Homepage (Opera Software)
- Manipulation of framed content can allow cross-site scripting (Opera Software)
- Script events can be used to reveal the presence of local files (Opera Software)