Opera Web Browser Cross Site Scripting Sanitizer Security Bypass Vulnerability
BID:54788
Info
Opera Web Browser Cross Site Scripting Sanitizer Security Bypass Vulnerability
| Bugtraq ID: | 54788 |
| Class: | Design Error |
| CVE: |
CVE-2012-4144 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2012 12:00AM |
| Updated: | Sep 25 2012 11:20PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
SuSE openSUSE 12.1 SuSE openSUSE 11.4 Opera Software Opera Web Browser 11.64 Opera Software Opera Web Browser 11.62 Opera Software Opera Web Browser 11.61 Opera Software Opera Web Browser 11.60 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Opera Web Browser Cross Site Scripting Sanitizer Security Bypass Vulnerability
Opera Web Browser is prone to a security-bypass vulnerability.
An attacker can exploit this vulnerability to bypass the cross-site scripting sanitizer. Successful exploits may allow attackers to execute arbitrary script code and steal cookie-based authentication credentials.
Opera Web Browser versions prior to 12.01 and 11.66 are vulnerable.
Opera Web Browser is prone to a security-bypass vulnerability.
An attacker can exploit this vulnerability to bypass the cross-site scripting sanitizer. Successful exploits may allow attackers to execute arbitrary script code and steal cookie-based authentication credentials.
Opera Web Browser versions prior to 12.01 and 11.66 are vulnerable.
Exploit / POC
Opera Web Browser Cross Site Scripting Sanitizer Security Bypass Vulnerability
Attackers can exploit these issues by enticing an unsuspecting user into visiting a specially crafted webpage.
Attackers can exploit these issues by enticing an unsuspecting user into visiting a specially crafted webpage.
Solution / Fix
Opera Web Browser Cross Site Scripting Sanitizer Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Opera Web Browser Cross Site Scripting Sanitizer Security Bypass Vulnerability
References:
References:
- Opera Homepage (Opera Software)