Title: Opera HTML Character Handling XSS Protection Bypass
Info
Disclosure
Aug 02, 2012
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Aug 02, 2012
Description
Opera contains a flaw that is triggered when an error occurs during the handling of certain HTML characters. This may allow a context-dependent attacker to bypass cross-site scripting (XSS) protection and more easily conduct XSS attacks.
Classification
Location:
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Private
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
Upgrade to version 11.66 for Mac or version 12.01 for all platforms or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.