Opera before 12.10 follows Internet shortcuts that are referenced by a (1) IMG element or (2) other inline element, which makes it easier for remote attackers to conduct phishing attacks via a crafted web site, as exploited in the wild in November 2012.
Link | Tags |
---|---|
http://www.opera.com/support/kb/view/1034/ | vendor advisory |
http://www.securityfocus.com/bid/57132 | vdb entry |
http://www.opera.com/docs/changelogs/unified/1210/ |