PC Ekspert Forum

PC Ekspert Forum (https://forum.pcekspert.com/index.php)
-   Aplikacije (https://forum.pcekspert.com/forumdisplay.php?f=37)
-   -   Opera (https://forum.pcekspert.com/showthread.php?t=11979)

RAK 10.08.2004. 00:07

Opera
 
Description: A vulnerability was reported in Opera in the processing of the 'location' object. A remote user can gain read access to the target user's file system.

GreyMagic Software reported that a remote user can create HTML that, when loaded by the target user, will be able to read files on the target user's system or run in the context of a remote domain.

This is achieved by loading HTML code that invokes a method within the vulnerable 'location' object and then replacing or overwriting a function with arbitrary scripting code. HTML code on the target user's file system or on remote web sites can be exploited.

To gain read access to files on the target user's system, the remote user can load an HTML file from a known location on the target user's system and then overwrite a method within that file.

The vendor was reportedly notified on July 22, 2004.

Some demonstration exploits and the original advisory are available at:

http://www.greymagic.com/security/advisories/gm008-op/

Impact: A remote user can access a target user's file system.

Solution: The vendor has released a fixed version (7.54), available at:

http://www.opera.com/download/

Amdejac 10.08.2004. 22:27

Jel moreš to povedati na zagorskom jeziku, a ak' napišeš na hrvackom bum si sam prevel.:D

RAK 11.08.2004. 00:12

Hiti u kantu novu verziju Opere (dobila naziv po onom skakutanju i urlanju u kuću strave i užasa).


Sva vremena su GMT +2. Sada je 19:26.

Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© 1999-2024 PC Ekspert - Sva prava pridržana ISSN 1334-2940
Ad Management by RedTyger