vendor:
Opera
by:
Aviv Raff
5.5
CVSS
MEDIUM
Remote Code Execution
CWE
Product Name: Opera
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Windows (specific versions not provided)
2008
Remote Code Execution in Opera
An attacker can change the default external mail application in Opera to execute code from a remote location. By changing the settings and setting the location to 'mailto:', the attacker can execute the code. A proof-of-concept is provided to execute the Windows Calculator.
Mitigation:
Upgrade to a newer version of Opera. There is no other known mitigation or remediation for this vulnerability.