Opera before 9.63 does not block unspecified "scripted URLs" during the feed preview, which allows remote attackers to read existing subscriptions and force subscriptions to arbitrary feed URLs.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2008-5652 | Opera before 9.63 does not block unspecified "scripted URLs" during the feed preview, which allows remote attackers to read existing subscriptions and force subscriptions to arbitrary feed URLs. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T11:04:44.147Z
Reserved: 2008-12-19T00:00:00
Link: CVE-2008-5681
No data.
Status : Deferred
Published: 2008-12-19T16:30:00.250
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-5681
No data.
OpenCVE Enrichment
No data.
EUVD