CVE-2010-4045

Opera < 10.63 - Cross-Site Scripting via Address Bar Spoofing

Title source: llm
STIX 2.1

Description

Opera before 10.63 does not properly restrict web script in unspecified circumstances involving reloads and redirects, which allows remote attackers to spoof the Address Bar, conduct cross-site scripting (XSS) attacks, and possibly execute arbitrary code by leveraging the ability of a script to interact with a web page from (1) a different domain or (2) a different security context.

References (7)

Core 7
Core References
Vendor Advisory x_refsource_confirm
http://www.opera.com/support/kb/view/973/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1024570
Vendor Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/mac/1063/
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/41740
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12071
Vendor Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/unix/1063/
Vendor Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/windows/1063/

Scores

EPSS 0.0352
EPSS Percentile 87.8%

Details

CWE
CWE-264
Status published
Products (30)
opera/opera_browser 5.0 (8 CPE variants)
opera/opera_browser 5.02
opera/opera_browser 5.10
opera/opera_browser 5.11
opera/opera_browser 5.12
opera/opera_browser 6.0 (6 CPE variants)
opera/opera_browser 6.1 (2 CPE variants)
opera/opera_browser 6.01
opera/opera_browser 6.02
opera/opera_browser 6.03
... and 20 more
Published Oct 21, 2010
Tracked Since Feb 18, 2026