PT-2004-2121 · Opera · Opera
Published
2004-12-10
·
Updated
2022-02-28
·
CVE-2004-1157
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Opera versions 7.x up to 7.54
Description:
The issue allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain. This can be demonstrated using a pop-up window on a trusted web site.
Recommendations:
For Opera versions 7.x up to 7.54, consider disabling pop-up windows as a temporary workaround until a patch is available. Restrict access to sensitive information in different domains to minimize the risk of exploitation.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opera