PT-2004-3383 · Opera · Opera

Published

2004-12-31

·

Updated

2022-02-28

·

CVE-2004-2491

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Opera web browser version 7.53 Build 3850
Description: A race condition issue allows remote attackers to spoof the URL in the address bar, facilitating phishing attacks. This is achieved via the window.open and location.replace HTML parameters.
Recommendations: For Opera web browser version 7.53 Build 3850, consider avoiding the use of the window.open and location.replace parameters in HTML until a fix is available. As a temporary workaround, restrict access to potentially malicious websites to minimize the risk of exploitation.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2004-2491

Affected Products

Opera