VulnerabilityModified
CVE-2008-5681
Opera before 9.63 does not block unspecified "scripted URLs" during the feed preview, which allows remote attackers to read existing subscriptions and force subscriptions to arbitrary feed URLs.
MEDIUM 4.3EPSS 1.10%
Does this matter?
Lower severity and a low EPSS score (1.10%). Track it; it rarely justifies an emergency change on its own.
Description
Opera before 9.63 does not block unspecified "scripted URLs" during the feed preview, which allows remote attackers to read existing subscriptions and force subscriptions to arbitrary feed URLs.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.10% probability · 64th percentile
- CISA KEV
- Not listed
- Affected
- opera/opera browser
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/34294
- http://security.gentoo.org/glsa/glsa-200903-30.xml
- http://www.opera.com/docs/changelogs/linux/963/
- http://www.opera.com/support/kb/view/923/Vendor Advisory
- http://www.securitytracker.com/id?1021461
- http://secunia.com/advisories/34294
- http://security.gentoo.org/glsa/glsa-200903-30.xml
- http://www.opera.com/docs/changelogs/linux/963/
- http://www.opera.com/support/kb/view/923/Vendor Advisory
- http://www.securitytracker.com/id?1021461
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.