
|
Title: |
Opera FTP View Cross-Site Scripting Vulnerability |
|
Date: |
4 August 2002 (Last modified: ) |
|
Author: |
Eiji James Yoshida [ptrs-ejy@bp.iij4u.or.jp] |
|
Risk: |
Medium |
|
Vulnerable: |
Windows2000 SP2 Opera 6.03 |
|
Not vulnerable: |
Opera 6.05 |
|
Bugtraq ID: |
|
|
Overview: |
Opera allows running Malicious Scripts due to a bug in 'FTP
view' feature.
|
|
Details: |
This problem is in 'FTP view' feature. |
|
Exploit code: |
<html> |
|
Demonstration: |
|
|
Workaround: |
Disable JavaScript. |
|
Vendor status: |
Opera Software ASA was notified on 30 June 2002. |
|
Similar vulnerabilities: |
Microsoft Internet Explorer 'Folder View for FTP sites' Script Execution Vulnerability |
Copyright(c) 2002 Eiji James Yoshida. All rights reserved