Vulnerability Description
Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript to read arbitrary files from the client's local filesystem or display a false URL to the user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opera | Opera Browser | < 7.54 |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0131.htmlBroken Link
- http://osvdb.org/8331Broken Link
- http://secunia.com/advisories/12233Broken LinkPatchVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200408-05.xmlPatchThird Party Advisory
- http://www.greymagic.com/security/advisories/gm008-op/Broken LinkExploitVendor Advisory
- http://www.opera.com/docs/changelogs/windows/754/Broken LinkPatch
- http://www.securityfocus.com/bid/10873Broken LinkPatchThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16904Third Party AdvisoryVDB Entry
- http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0131.htmlBroken Link
- http://osvdb.org/8331Broken Link
- http://secunia.com/advisories/12233Broken LinkPatchVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200408-05.xmlPatchThird Party Advisory
- http://www.greymagic.com/security/advisories/gm008-op/Broken LinkExploitVendor Advisory
- http://www.opera.com/docs/changelogs/windows/754/Broken LinkPatch
- http://www.securityfocus.com/bid/10873Broken LinkPatchThird Party Advisory
FAQ
What is CVE-2004-2570?
CVE-2004-2570 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript to read arbitrary files from the client's local filesystem or display a false U...
How severe is CVE-2004-2570?
CVE-2004-2570 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2570?
Check the references section above for vendor advisories and patch information. Affected products include: Opera Opera Browser.