vendor:
Opera
by:
Security-Assessment.com
9.3
CVSS
HIGH
Stored Cross Site Scripting
79
CWE
Product Name: Opera
Affected Version From: All desktop versions
Affected Version To: All desktop versions
Patch Exists: Yes
Related CWE: CVE-2008-4609
CPE: a:opera_software:opera
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2008
Opera Stored Cross Site Scripting Vulnerability
Opera browser is vulnerable to stored Cross Site Scripting. A malicious attacker is able to inject arbitrary browser content through the websites visited with the Opera browser. The code injection is rendered into the Opera History Search page which displays URL and a short description of the visited pages.
Mitigation:
Opera Software has released a patch to address this vulnerability.