Back to search
CVE-2012-1926
Published: Mar 28, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
Opera before 11.62 allows remote attackers to bypass the Same Origin Policy via the (1) history.pushState and (2) history.replaceState functions in conjunction with cross-domain frames, leading to unintended read access to history.state information.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.opera.com/support/kb/view/1012/
x_refsource_CONFIRM
http://www.opera.com/docs/changelogs/mac/1162/
x_refsource_CONFIRM
80622
vdb-entry
x_refsource_OSVDB
http://www.opera.com/docs/changelogs/windows/1162/
x_refsource_CONFIRM
openSUSE-SU-2012:0610
vendor-advisory
x_refsource_SUSE
http://www.opera.com/docs/changelogs/unix/1162/
x_refsource_CONFIRM
opera-historypushstate-info-disclosure(74351)
vdb-entry
x_refsource_XF
48535
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now