PT-2005-2646 · Opera · Opera

Published

2005-06-16

·

Updated

2022-02-28

·

CVE-2005-1669

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Opera version 8.0 Final Build 1095
Description The issue allows remote attackers to inject arbitrary web script or HTML via javascript: URLs when a new window or frame is opened. This enables attackers to bypass access restrictions and perform unauthorized actions on other domains. The problem exists because the application does not restrict the privileges of javascript: URLs when opened in new windows or frames, which could allow a user to create specially crafted HTML that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity or confidentiality.
Recommendations For Opera version 8.0 Final Build 1095, consider disabling the execution of javascript: URLs in new windows or frames as a temporary workaround until a patch is available. Restrict access to sensitive domains and resources to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2005-1669

Affected Products

Opera