Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-4696
Description:Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "optional fragment"), which is not properly escaped before storage in the History Search database (aka md.dat).
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-4696
BugTraq ID: 31869
http://www.securityfocus.com/bid/31869
Bugtraq: 20081022 Opera Stored Cross Site Scripting Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/497646/100/0/threaded
https://www.exploit-db.com/exploits/6801
http://security.gentoo.org/glsa/glsa-200811-01.xml
http://www.security-assessment.com/files/advisories/2008-10-22_Opera_Stored_Cross_Site_Scripting.pdf
http://www.openwall.com/lists/oss-security/2008/10/21/6
http://www.openwall.com/lists/oss-security/2008/10/22/5
http://secunia.com/advisories/32299
http://secunia.com/advisories/32394
http://secunia.com/advisories/32538
http://securityreason.com/securityalert/4504
SuSE Security Announcement: SUSE-SR:2008:022 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00009.html
http://www.vupen.com/english/advisories/2008/2873
XForce ISS Database: opera-historysearch-xss(46003)
https://exchange.xforce.ibmcloud.com/vulnerabilities/46003




© 1998-2025 E-Soft Inc. All rights reserved.