Secunia Logo
 
CVE Reference: CVE-2005-3006
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-3006

Description:
The mail client in Opera before 8.50 opens attached files from the user's cache directory without warning the user, which might allow remote attackers to inject arbitrary web script and spoof attachment filenames.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/22335

SUSE
  http://www.novell.com/linux/security/advisories/2005_57_opera.html
  http://www.securityfocus.com/advisories/9339

SAID
  Secunia Advisory: SA16645

OSVDB
  19508

MISC
  http://secunia.com/secunia_research/2005-42/advisory/

CONFIRM
  http://www.opera.com/docs/changelogs/windows/850/
  http://www.opera.com/docs/changelogs/linux/850/

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=112724692219695&w=2

BID
  14880


Return to the previous page.