4.3

CVE-2008-4795

Exploit

The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inject arbitrary web script or HTML via cross-site scripting (XSS) attacks.

Data is provided by the National Vulnerability Database (NVD)
OperaOpera Version <= 9.61
OperaOpera Version5..10
OperaOpera Version5.0
OperaOpera Version5.1
OperaOpera Version5.2
OperaOpera Version5.3
OperaOpera Version5.4
OperaOpera Version5.5
OperaOpera Version5.6
OperaOpera Version5.7
OperaOpera Version5.8
OperaOpera Version5.9
OperaOpera Version5.11
OperaOpera Version5.12
OperaOpera Version6 Updatebeta_1
OperaOpera Version6.0
OperaOpera Version6.01
OperaOpera Version6.02
OperaOpera Version6.03
OperaOpera Version6.04
OperaOpera Version6.05
OperaOpera Version6.06
OperaOpera Version7 Updatebeta_1
OperaOpera Version7 Updatebeta_1.2
OperaOpera Version7.0
OperaOpera Version7.0 Updatebeta_2
OperaOpera Version7.01
OperaOpera Version7.02
OperaOpera Version7.03
OperaOpera Version7.10
OperaOpera Version7.11
OperaOpera Version7.20
OperaOpera Version7.20 Updatebeta7
OperaOpera Version7.21
OperaOpera Version7.22
OperaOpera Version7.23
OperaOpera Version7.50
OperaOpera Version7.50 Updatebeta_1
OperaOpera Version7.51
OperaOpera Version7.52
OperaOpera Version7.53
OperaOpera Version7.54
OperaOpera Version7.54 Updateupdate_1
OperaOpera Version7.54 Updateupdate_2
OperaOpera Version8.0
OperaOpera Version8.0 Updatebeta_1
OperaOpera Version8.0 Updatebeta_2
OperaOpera Version8.0 Updatebeta_3
OperaOpera Version8.01
OperaOpera Version8.02
OperaOpera Version8.50
OperaOpera Version8.51
OperaOpera Version8.52
OperaOpera Version8.53
OperaOpera Version8.54
OperaOpera Version9.0
OperaOpera Version9.0 Updatebeta_1
OperaOpera Version9.0 Updatebeta_2
OperaOpera Version9.01
OperaOpera Version9.02
OperaOpera Version9.10
OperaOpera Version9.20
OperaOpera Version9.20 Updatebeta_1
OperaOpera Version9.21
OperaOpera Version9.22
OperaOpera Version9.23
OperaOpera Version9.24
OperaOpera Version9.25
OperaOpera Version9.26
OperaOpera Version9.27
OperaOpera Version9.50
OperaOpera Version9.50 Updatebeta_2
OperaOpera Version9.51
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 9.73% 0.921
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.