Summary
This host is installed with Opera and is prone to multiple vulnerabilities.
Impact
Successful exploitation will allow remote attackers to execute arbitrary script code, disclose sensitive information, or spoof the originating URL of a trusted web site and carry out phishing-style attacks.
Impact Level: Application
Solution
Upgrade to Opera version 11.66 or 12.01 or later,
For updates refer to http://www.opera.com/
Insight
- Multiple unspecified errors.
- An error when certain characters in HTML documents are ignored under some circumstances, which allows to conduct XSS attacks.
- The improper implementation of download dialog feature, which allows attackers to trick users into downloading and executing arbitrary files via a small window for the download dialog.
- Fails to escape characters in DOM elements, which allows to conduct XSS attacks.
Affected
Opera version prior to 11.66 and 12.x before 12.01 on Mac OS X
References
Severity
Classification
-
CVE CVE-2012-4142, CVE-2012-4143, CVE-2012-4144, CVE-2012-4145 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities