|
Family: Windows --> Category: infos
Opera < 8.50 Multiple Vulnerabilities Vulnerability Scan
Vulnerability Scan Summary Checks for multiple vulnerabilities in Opera < 8.50
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote host contains a web browser which is vulnerable to
attachment spoofing, script insertion and unintentional file uploads.
Description :
The remote host is using Opera, an alternative web browser.
The installed version of Opera on the remote host contains two flaws
its mail client and one in the browser. First, message attachments
are opened from the user's cache directory without any warnings, which
can be exploited to execute arbitrary Javascript within the context of
'file://'. Second, appending an additional '.' to an attachment's
filename causes the file type to be spoofed. And third, the browser
is affected by an unspecified drag-and-drop vulnerability that
facilitates unintentional file uploads.
See also :
http://secunia.com/secunia_research/2005-42/advisory/
http://www.opera.com/docs/changelogs/windows/850/
Solution :
Upgrade to Opera 8.50 or later.
Threat Level:
Medium / CVSS Base Score : 4
(AV:R/AC:H/Au:NR/C:P/A:N/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|