Record summary

CVE-2004-2491 has a selected CVSS score of 2.6; EIP currently links 1 catalogued exploit.

Description

A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing attacks.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBOpera Web Browser 7.53 - Location Replace URI ObfuscationExploitDB exploitby bitlance winterNot analyzed1 file
ExploitDB

PoC details

References

7