The mail client in Opera before 8.50 opens attached files from the user's cache directory without warning the user, which might allow remote attackers to inject arbitrary web script and spoof attachment filenames.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2005/1789 | vdb entry |
http://www.securityfocus.com/bid/14880 | vdb entry |
http://secunia.com/secunia_research/2005-42/advisory/ | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/22335 | vdb entry |
http://www.opera.com/docs/changelogs/windows/850/ | |
http://www.opera.com/docs/changelogs/linux/850/ | |
http://www.securityfocus.com/advisories/9339 | vendor advisory |
http://marc.info/?l=bugtraq&m=112724692219695&w=2 | mailing list |
http://www.osvdb.org/19508 | vdb entry patch |
http://secunia.com/advisories/16645 | third party advisory patch vendor advisory |