Description
Opera before 9.52 does not ensure that the address field of a news feed represents the feed's actual URL, which allows remote attackers to change this field to display the URL of a page containing web script controlled by the attacker.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2008-4183 | Opera before 9.52 does not ensure that the address field of a news feed represents the feed's actual URL, which allows remote attackers to change this field to display the URL of a page containing web script controlled by the attacker. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T10:08:34.950Z
Reserved: 2008-09-23T00:00:00.000Z
Link: CVE-2008-4200
No data.
Status : Modified
Published: 2008-09-27T10:30:03.507
Modified: 2026-04-23T00:35:47.467
Link: CVE-2008-4200
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD