20040726 Opera 7.53 (Build 3850) Address Bar Spoofing Issuemailing list
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/1056.html CVE-2004-2491
Opera Web Browser 7.53 - Location Replace URI Obfuscation
Record summary
CVE-2004-2491 has a selected CVSS score of 2.6; EIP currently links 1 catalogued exploit.
Description
A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing attacks.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOpera Web Browser 7.53 - Location Replace URI ObfuscationExploitDB exploitby bitlance winterNot analyzed1 file
References
712162Third-party advisory
http://secunia.com/advisories/12162 opera.comConfirmation
http://www.opera.com/windows/changelogs/754 8317vdb entry
http://www.osvdb.org/8317 10810vdb entry
http://www.securityfocus.com/bid/10810 opera-addressbar-spoofing(16816)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16816 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2491