PT-2005-3843 · Opera · Opera

Jakob Balle

·

Published

2005-09-21

·

Updated

2017-07-11

·

CVE-2005-3006

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Opera versions prior to 8.50
Description The issue allows remote attackers to inject arbitrary web script and potentially spoof attachment filenames by opening attached files from the user's cache directory without warning. This might occur when arbitrary JavaScript is executed in the context of "file://", potentially leading to a loss of confidentiality if a user chooses to view an attachment.
Recommendations For Opera versions prior to 8.50, update to version 8.50 or later to resolve the issue. As a temporary workaround, consider avoiding the execution of arbitrary JavaScript in the context of "file://" and be cautious when viewing attachments to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3006

Affected Products

Opera