Oval Definition:oval:org.mitre.oval:def:6314
Revision Date:2014-03-17Version:7
Title:Opera 9 and 10 allows remote attackers to conduct XSS Vulnerability
Description:Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to conduct cross-site scripting (XSS) attacks, and conduct cross-zone scripting attacks involving the Feed Subscription Page to read feeds or create feed subscriptions, via a crafted feed, related to the rendering of the application/rss+xml content type as "scripted content."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2009-3266
Platform(s):Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Opera Browser
Definition Synopsis
  • Opera Browser is installed
  • AND Opera.exe version 9.x to 10.0.x
  • AND Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists
  • BACK