FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-4725

This CVE name corresponds to:

Entered Topic
2008-10-28 opera -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-4725
Phase Assigned(20081023)

Description

Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly escaped before storage in the History Search database (aka md.dat), a different vector than CVE-2008-4696. NOTE: some of these issues were addressed before 9.60.

References

Source Reference
BUGTRAQ 20081022 Opera Stored Cross Site Scripting Vulnerability
MILW0RM 6801
MLIST [oss-security] 20081021 Re: CVE Request: Opera 9.60 with security fixes
MLIST [oss-security] 20081022 Re: CVE Request: Opera 9.60 with security fixes
MISC http://www.opera.com/docs/changelogs/freebsd/961/
MISC http://www.opera.com/docs/changelogs/linux/961/
MISC http://www.opera.com/docs/changelogs/mac/961/
MISC http://www.opera.com/docs/changelogs/solaris/961/
MISC http://www.opera.com/docs/changelogs/windows/961/
MISC http://www.opera.com/support/search/view/903/
MISC http://www.security-assessment.com/files/advisories/2008-10-22_Opera_Stored_Cross_Site_Scripting.pdf
CONFIRM http://www.opera.com/support/search/view/903/
BID 31869
VUPEN ADV-2008-2873
SECUNIA 32299
SREASON 4504
XF opera-historysearch-xss(46003)
XF opera-opera-querystring-xss(46231)