CVE-2007-1115

Opera <9.20 - XSS

Title source: llm

Description

The child frames in Opera 9 before 9.20 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.

Scores

EPSS 0.0083
EPSS Percentile 74.3%

Classification

CWE
CWE-79
Status draft

Affected Products (9)

opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser

Timeline

Published Feb 26, 2007
Tracked Since Feb 18, 2026