CVE-2008-4696
Opera - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "optional fragment"), which is not properly escaped before storage in the History Search database (aka md.dat).
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by egypt · rubyremotemultiple
https://www.exploit-db.com/exploits/9944
metasploit
WORKING POC
EXCELLENT
by Roberto Suggi · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/opera_historysearch.rb
exploitdb
WRITEUP
VERIFIED
by Roberto Suggi Liverani · textremotewindows
https://www.exploit-db.com/exploits/6801
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16304
References (20)
Scores
EPSS
0.6212
EPSS Percentile
98.3%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
opera/opera
... and 35 more
Timeline
Published
Oct 23, 2008
Tracked Since
Feb 18, 2026