Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-4725
Description:Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly escaped before storage in the History Search database (aka md.dat), a different vector than CVE-2008-4696. NOTE: some of these issues were addressed before 9.60.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-4725
BugTraq ID: 31869
http://www.securityfocus.com/bid/31869
Bugtraq: 20081022 Opera Stored Cross Site Scripting Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/497646/100/0/threaded
https://www.exploit-db.com/exploits/6801
http://www.opera.com/docs/changelogs/freebsd/961/
http://www.opera.com/docs/changelogs/linux/961/
http://www.opera.com/docs/changelogs/mac/961/
http://www.opera.com/docs/changelogs/solaris/961/
http://www.opera.com/docs/changelogs/windows/961/
http://www.security-assessment.com/files/advisories/2008-10-22_Opera_Stored_Cross_Site_Scripting.pdf
http://www.openwall.com/lists/oss-security/2008/10/21/6
http://www.openwall.com/lists/oss-security/2008/10/22/5
http://secunia.com/advisories/32299
http://securityreason.com/securityalert/4504
http://www.vupen.com/english/advisories/2008/2873
XForce ISS Database: opera-historysearch-xss(46003)
https://exchange.xforce.ibmcloud.com/vulnerabilities/46003
XForce ISS Database: opera-opera-querystring-xss(46231)
https://exchange.xforce.ibmcloud.com/vulnerabilities/46231




© 1998-2025 E-Soft Inc. All rights reserved.