CVE-2008-4725
Opera 9.60 - Persistent Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly escaped before storage in the History Search database (aka md.dat), a different vector than CVE-2008-4696. NOTE: some of these issues were addressed before 9.60.
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Opera.dll de Opera v9.52 permite a atacantes remotos inyectar web script o HTML a través de la cadena de consulta, la cual no está escapada adecuadamente antes de su almacenamiento en la base de datos History Search (también conocido como md.dat), un vector diferente a CVE-2008-4696.
NOTA: alguna de estas cuestiones se nos enviaron antes de v9.60.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-10-23 CVE Reserved
- 2008-10-23 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (17)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/4504 | Third Party Advisory | |
http://www.openwall.com/lists/oss-security/2008/10/21/6 | Mailing List | |
http://www.openwall.com/lists/oss-security/2008/10/22/5 | Mailing List | |
http://www.opera.com/docs/changelogs/freebsd/961 | X_refsource_misc | |
http://www.opera.com/docs/changelogs/linux/961 | X_refsource_misc | |
http://www.opera.com/docs/changelogs/mac/961 | X_refsource_misc | |
http://www.opera.com/docs/changelogs/solaris/961 | X_refsource_misc | |
http://www.opera.com/docs/changelogs/windows/961 | X_refsource_misc | |
http://www.opera.com/support/search/view/903 | X_refsource_confirm | |
http://www.security-assessment.com/files/advisories/2008-10-22_Opera_Stored_Cross_Site_Scripting.pdf | X_refsource_misc | |
http://www.securityfocus.com/archive/1/497646/100/0/threaded | Mailing List | |
http://www.vupen.com/english/advisories/2008/2873 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46003 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46231 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/6801 | 2024-08-07 | |
http://www.securityfocus.com/bid/31869 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/32299 | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Opera Search vendor "Opera" | Opera Browser Search vendor "Opera" for product "Opera Browser" | 9.52 Search vendor "Opera" for product "Opera Browser" and version "9.52" | - |
Affected
|