CVE-2004-1157
7.5
CVSS Score
High
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Link copied!
Description
Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
P
Availability
P
Affected Software Configurations
- a opera opera_browser * * * * * * * *
Weaknesses (CWE)
- CWE-74
References & External Links
- http://secunia.com/advisories/13253/
- http://secunia.com/multiple_browsers_window_injection_vulnerability_test/
- http://secunia.com/secunia_research/2004-13/advisory/
- http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml
- http://secunia.com/advisories/13253/
- http://secunia.com/multiple_browsers_window_injection_vulnerability_test/
- http://secunia.com/secunia_research/2004-13/advisory/
- http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml
External Resources
CVE History Timeline
Jan 01, 2004 05:00
Initial Analysis
Feb 28, 2022 18:38
Reanalysis
May 14, 2024 01:26
CVE Modified
Nov 20, 2024 23:50
CVE Modified