The XMLHttpRequest object in Opera 8.0 Final Build 1095 allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains via a redirect.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/13970 | vdb entry third party advisory broken link |
http://secunia.com/advisories/15008 | broken link third party advisory patch vendor advisory |
http://secunia.com/secunia_research/2005-4/advisory/ | patch vendor advisory broken link |