CVE-2008-4696

Opera - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "optional fragment"), which is not properly escaped before storage in the History Search database (aka md.dat).

Exploits (4)

exploitdb WORKING POC VERIFIED
by egypt · rubyremotemultiple
https://www.exploit-db.com/exploits/9944
metasploit WORKING POC EXCELLENT
by Roberto Suggi · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/opera_historysearch.rb
exploitdb WRITEUP VERIFIED
by Roberto Suggi Liverani · textremotewindows
https://www.exploit-db.com/exploits/6801
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16304

Scores

EPSS 0.6212
EPSS Percentile 98.3%

Classification

CWE
CWE-79
Status published

Affected Products (50)

opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
... and 35 more

Timeline

Published Oct 23, 2008
Tracked Since Feb 18, 2026