PT-2004-3383 · Opera · Opera
Published
2004-12-31
·
Updated
2022-02-28
·
CVE-2004-2491
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Opera web browser version 7.53 Build 3850
Description:
A race condition issue allows remote attackers to spoof the URL in the address bar, facilitating phishing attacks. This is achieved via the
window.open and location.replace HTML parameters.Recommendations:
For Opera web browser version 7.53 Build 3850, consider avoiding the use of the
window.open and location.replace parameters in HTML until a fix is available. As a temporary workaround, restrict access to potentially malicious websites to minimize the risk of exploitation.Exploit
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opera