OpenBSD VuXML: Documenting security issues in the OpenBSD Ports & Packages Collection

opera -- frame injection vulnerability

Affected packages
opera < 7.52

Details

VuXML ID c3abac88-d029-11d8-92cb-00304f19272c
Discovery 2003-07-01
Entry 2004-07-07

A 6 year old vulnerability has been discovered in multiple browsers, allowing malicious people to spoof the content of websites. The problem is that the browsers don't check if a target frame belongs to a website containing a malicious link, which therefore doesn't prevent one browser window from loading content in a named frame in another window. Successful exploitation allows a malicious website to load arbitrary content in an arbitrary frame in another browser window owned by e.g. a trusted site.

References

URL http://secunia.com/advisories/11978