4.3

CVE-2008-4696

Exploit

Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "optional fragment"), which is not properly escaped before storage in the History Search database (aka md.dat).

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OperaOpera
OperaOpera Version <= 9.6
OperaOpera Version5..10
OperaOpera Version5.0
OperaOpera Version5.1
OperaOpera Version5.2
OperaOpera Version5.3
OperaOpera Version5.4
OperaOpera Version5.5
OperaOpera Version5.6
OperaOpera Version5.7
OperaOpera Version5.8
OperaOpera Version5.9
OperaOpera Version5.11
OperaOpera Version5.12
OperaOpera Version6 Updatebeta_1
OperaOpera Version6.0
OperaOpera Version6.01
OperaOpera Version6.02
OperaOpera Version6.03
OperaOpera Version6.04
OperaOpera Version6.05
OperaOpera Version6.06
OperaOpera Version7 Updatebeta_1
OperaOpera Version7 Updatebeta_1.2
OperaOpera Version7.0
OperaOpera Version7.0 Updatebeta_2
OperaOpera Version7.01
OperaOpera Version7.02
OperaOpera Version7.03
OperaOpera Version7.10
OperaOpera Version7.11
OperaOpera Version7.20
OperaOpera Version7.20 Updatebeta7
OperaOpera Version7.21
OperaOpera Version7.22
OperaOpera Version7.23
OperaOpera Version7.50
OperaOpera Version7.50 Updatebeta_1
OperaOpera Version7.51
OperaOpera Version7.52
OperaOpera Version7.53
OperaOpera Version7.54
OperaOpera Version7.54 Updateupdate_1
OperaOpera Version7.54 Updateupdate_2
OperaOpera Version8.0
OperaOpera Version8.0 Updatebeta_1
OperaOpera Version8.0 Updatebeta_2
OperaOpera Version8.0 Updatebeta_3
OperaOpera Version8.01
OperaOpera Version8.02
OperaOpera Version8.50
OperaOpera Version8.51
OperaOpera Version8.52
OperaOpera Version8.53
OperaOpera Version8.54
OperaOpera Version9.0
OperaOpera Version9.0 Updatebeta_1
OperaOpera Version9.0 Updatebeta_2
OperaOpera Version9.01
OperaOpera Version9.02
OperaOpera Version9.10
OperaOpera Version9.20
OperaOpera Version9.20 Updatebeta_1
OperaOpera Version9.21
OperaOpera Version9.22
OperaOpera Version9.23
OperaOpera Version9.24
OperaOpera Version9.25
OperaOpera Version9.26
OperaOpera Version9.27
OperaOpera Version9.50
OperaOpera Version9.50 Updatebeta_2
OperaOpera Version9.51
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 62.12% 0.982
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.