CVE-2008-4795
30.10.2008, 20:56
The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inject arbitrary web script or HTML via cross-site scripting (XSS) attacks.
Vendor | Product | Version |
---|---|---|
opera | opera | 𝑥 ≤ 9.61 |
opera | opera | 5..10 |
opera | opera | 5.0 |
opera | opera | 5.1 |
opera | opera | 5.2 |
opera | opera | 5.3 |
opera | opera | 5.4 |
opera | opera | 5.5 |
opera | opera | 5.6 |
opera | opera | 5.7 |
opera | opera | 5.8 |
opera | opera | 5.9 |
opera | opera | 5.11 |
opera | opera | 5.12 |
opera | opera | 6.0 |
opera | opera | 6.01 |
opera | opera | 6.02 |
opera | opera | 6.03 |
opera | opera | 6.04 |
opera | opera | 6.05 |
opera | opera | 6.06 |
opera | opera | 7.0 |
opera | opera | 7.0:beta_2 |
opera | opera | 7.01 |
opera | opera | 7.02 |
opera | opera | 7.03 |
opera | opera | 7.10 |
opera | opera | 7.11 |
opera | opera | 7.20 |
opera | opera | 7.20:beta7 |
opera | opera | 7.21 |
opera | opera | 7.22 |
opera | opera | 7.23 |
opera | opera | 7.50 |
opera | opera | 7.50:beta_1 |
opera | opera | 7.51 |
opera | opera | 7.52 |
opera | opera | 7.53 |
opera | opera | 7.54 |
opera | opera | 7.54:update_1 |
opera | opera | 7.54:update_2 |
opera | opera | 8.0 |
opera | opera | 8.0:beta_1 |
opera | opera | 8.0:beta_2 |
opera | opera | 8.0:beta_3 |
opera | opera | 8.01 |
opera | opera | 8.02 |
opera | opera | 8.50 |
opera | opera | 8.51 |
opera | opera | 8.52 |
opera | opera | 8.53 |
opera | opera | 8.54 |
opera | opera | 9.0 |
opera | opera | 9.0:beta_1 |
opera | opera | 9.0:beta_2 |
opera | opera | 9.01 |
opera | opera | 9.02 |
opera | opera | 9.10 |
opera | opera | 9.20 |
opera | opera | 9.20:beta_1 |
opera | opera | 9.21 |
opera | opera | 9.22 |
opera | opera | 9.23 |
opera | opera | 9.24 |
opera | opera | 9.25 |
opera | opera | 9.26 |
opera | opera | 9.27 |
opera | opera | 9.50 |
opera | opera | 9.50:beta_2 |
opera | opera | 9.51 |
𝑥
= Vulnerable software versions
References