Opera Arbitrary File Disclosure...

- AV AC AU C I A
发布: 2002-05-27
修订: 2025-04-13

A vulnerability has been reported in Opera 6.01/6.02. The vulnerability is related to handling of the 'file' HTML input-type. It is possible for a server to set the file value, while fooling Opera into thinking no file has been specified. This is possible if the filename is appended with the string "
". This HTML-encoded newline character will cause the browser to believe that no value has been set. Consequently, the form will be submitted and the specified file will be uploaded to the server. This may occur without knowledge or consent of the victim user. Exploitation of this vulnerability allows for malicious webmasters to obtain arbitrary files from client systems.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息