4.3
CVSSv2

CVE-2008-4696

Published: 23/10/2008 Updated: 11/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 445
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Opera.dll in Opera prior to 9.61 allows remote malicious users to inject arbitrary web script or HTML via the anchor identifier (aka the "optional fragment"), which is not properly escaped before storage in the History Search database (aka md.dat).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opera opera 9.20

opera opera 9.10

opera opera 9.02

opera opera 8.52

opera opera 8.51

opera opera 8.0

opera opera 7.54

opera opera 7.50

opera opera 7.21

opera opera 7.0

opera opera 7.03

opera opera 6.05

opera opera 6.04

opera opera 5.2

opera opera 5.1

opera opera 9.50

opera opera 9.51

opera opera

opera opera 9.21

opera opera 9.22

opera opera 9.01

opera opera 9.0

opera opera 8.50

opera opera 8.02

opera opera 7.20

opera opera 7.22

opera opera 7

opera opera 7.02

opera opera 6

opera opera 5.0

opera opera 5.8

opera opera 5.7

opera opera 5.12

opera opera 5.11

opera opera 9.27

opera opera 9.23

opera opera 9.24

opera opera 8.01

opera opera 7.52

opera opera 7.53

opera opera 7.10

opera opera 6.06

opera opera 6.01

opera opera 6.0

opera opera 5.6

opera opera 5.5

opera opera 5..10

opera opera 5.9

opera opera 9.25

opera opera 9.26

opera opera 8.54

opera opera 8.53

opera opera 7.51

opera opera 7.11

opera opera 7.23

opera opera 7.01

opera opera 6.03

opera opera 6.02

opera opera 5.4

opera opera 5.3

Exploits

======================================================================= = Opera Stored Cross Site Scripting Vulnerability = = Vendor Website: = wwwoperacom = = Affected Version: = -- All desktop versions = = Public disclosure on 22nd October 2008 = ======================================================================== Available online ...
## # $Id$ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/projects/Framework/ ## require 'msf/core' class Metasploit3 < Msf::Exploit::Remote i ...
## # $Id: opera_historysearchrb 10998 2010-11-11 22:43:22Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' c ...