Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/98004 | vdb entry third party advisory |
http://abhikafle.com.np/opera-url-spoofing-poc/ | third party advisory exploit |