CVE-2007-1115
Opera <9.20 - XSS
Title source: llmDescription
The child frames in Opera 9 before 9.20 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.
References (10)
Scores
EPSS
0.0083
EPSS Percentile
74.3%
Classification
CWE
CWE-79
Status
draft
Affected Products (9)
opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser
Timeline
Published
Feb 26, 2007
Tracked Since
Feb 18, 2026