Document Title: =============== Opera Website - Cross Site Scripting Vulnerability References (Source): ==================== http://www.vulnerability-lab.com/get_content.php?id=369 Release Date: ============= 2012-01-23 Vulnerability Laboratory ID (VL-ID): ==================================== 369 Common Vulnerability Scoring System: ==================================== 3.3 Product & Service Introduction: =============================== Opera is a web browser and Internet suite developed by Opera Software with over 200 million users worldwide. The browser handles common Internet-related tasks such as displaying web sites, sending and receiving e-mail messages, managing contacts, chatting on IRC, downloading files via BitTorrent, and reading web feeds. Opera is offered free of charge for personal computers and mobile phones. (Copy of the Vendor Homepage: http://en.wikipedia.org/wiki/Opera_%28web_browser%29 ) Abstract Advisory Information: ============================== The Vulnerability-Lab researcher discovered a non persistant cross site scripting vulnerability on the Opera website. Vulnerability Disclosure Timeline: ================================== 2011-12-27: Vendor Notification 2011-12-30: Vendor Response/Feedback 2012-01-18: Vendor Fix/Patch 2012-01-24: Public or Non-Public Disclosure Discovery Status: ================= Published Affected Product(s): ==================== Exploitation Technique: ======================= Remote Severity Level: =============== Low Technical Details & Description: ================================ A non persistant cross site scripting vulnerability is detected on the Opera website. The vulnerability allows remote attackers to hijack users sessions via cross site scripting. Successful exploitation of the client-side vulnerability can result in session hijacking & account steal. Vulnerable Module(s): [+] ID Picture(s): ../1.png Proof of Concept (PoC): ======================= The vulnerability can be exploited by remote attackers with user inter action. For demonstration or reproduce ... PoC: client-side opera website vulnerability