CVE-2008-4795

Opera < 9.61 - XSS

Title source: rule
STIX 2.1

Description

The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inject arbitrary web script or HTML via cross-site scripting (XSS) attacks.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stefano Di Paola · htmlremotelinux
https://www.exploit-db.com/exploits/32548

References (7)

Core 7
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32538
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1021127
Vendor Advisory x_refsource_confirm
http://www.opera.com/support/search/view/907/
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46220
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31991
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200811-01.xml

Scores

EPSS 0.1116
EPSS Percentile 93.5%

Details

CWE
CWE-79
Status published
Products (41)
opera/opera 5..10
opera/opera 5.0
opera/opera 5.1
opera/opera 5.2
opera/opera 5.3
opera/opera 5.4
opera/opera 5.5
opera/opera 5.6
opera/opera 5.7
opera/opera 5.8
... and 31 more
Published Oct 30, 2008
Tracked Since Feb 18, 2026