PDA

View Full Version : Opera "data:" URI Handler Spoofing Vulnerability


ronjor
January 12th, 2005, 02:23 PM
Moderately critical
Unpatched-{ Quote: "The vulnerability is caused due to an error in the processing of "data:" URIs, causing wrong information to be shown in a download dialog. This can be exploited by e.g. a malicious website to trick users into executing a malicious file by supplying a specially crafted "data:" URI." }-Secunia (http://secunia.com/advisories/13818/)