Opera Web Browser 8.0/8.5 - HTML Form Status Bar Misrepresentation



EKU-ID: 31842 CVE: OSVDB-ID:
Author: Sverx Published: 2005-11-16 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/15472/info

A vulnerability has been identified in Opera Web browser that allows an attacker to misrepresent the status bar in the browser, allowing vulnerable users to be mislead into following a link to a malicious site.

This vulnerability would most likely be exploited through HTML e-mail, though other attack vectors exist such as HTML injection attacks in third-party Web applications.

<form action="[malicious site]">
<a href="www.example.com"><input type="image" src="[image]" title="www.example.com"></a>
</form>