The Fast Forward feature in Opera before 9.61, when a page is located
in a frame, executes a javascript: URL in the context of the outermost
page instead of the page that contains this URL, which allows remote
attackers to conduct cross-site scripting (XSS) attacks.