Release date: 2012-08-02
Updated on:
Affected Systems:
Opera Software Opera Web Browser 12.x
Opera Software Opera Web Browser 11.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54779
Opera is a browser from Norway.
The implementation of Opera Web Browser 12.01 and earlier versions has the HTML injection vulnerability. Attackers can exploit this vulnerability to execute arbitrary code in affected applications, steal Cookie authentication creden。, or control the appearance of the site.
<* Source: vendor
Link: http://secunia.com/advisories/50044/
Http://www.opera.com/support/kb/view/1025/
Http://www.opera.com/support/kb/view/1026/
Http://www.opera.com/support/kb/view/1027/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Opera Software
--------------
Opera Software has released a Security Bulletin (1025) and corresponding patches for this:
1025: Advisory: Element HTML content can be incorrectly returned without escaping, bypassing some HTML sanitizers
Link: http://www.opera.com/support/kb/view/1025/