FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

opera -- Data URIs can be used to allow cross-site scripting

Affected packages
opera < 10.11
opera-devel <= 10.20_2,1

Details

VuXML ID 77b9f9bc-7fdf-11df-8a8d-0008743bf21a
Discovery 2010-06-21
Entry 2010-06-25

The Opera Desktop Team reports:

Data URIs are allowed to run scripts that manipulate pages from the site that directly opened them. In some cases, the opening site is not correctly detected. In these cases, Data URIs may erroneously be able to run scripts so that they interact with sites that did not directly cause them to be opened.

References

URL http://www.opera.com/support/kb/view/955/