Opera Web Browser 8.0/8.5 - HTML Form Status Bar Misrepresentation

EDB-ID:

26531

CVE:

N/A


Author:

Sverx

Type:

remote


Platform:

Multiple

Date:

2005-11-16


source: https://www.securityfocus.com/bid/15472/info

A vulnerability has been identified in Opera Web browser that allows an attacker to misrepresent the status bar in the browser, allowing vulnerable users to be mislead into following a link to a malicious site.

This vulnerability would most likely be exploited through HTML e-mail, though other attack vectors exist such as HTML injection attacks in third-party Web applications. 

<form action="[malicious site]">
<a href="www.example.com"><input type="image" src="[image]" title="www.example.com"></a>
</form>