New Search

Information Disclosure in Opera before 10.54 due to failure to restrict access to the full pathname of a file selected for upload.

oval:org.mitre.oval:def:11669

Opera before 10.54 on Windows and Mac OS X and before 10.60 on UNIX platforms does not properly restrict access to the full pathname of a file selected for upload which allows remote attackers to obtain potentially sensitive information via unspecified DOM manipulations.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows 7
  • Microsoft Windows 2000
  • Microsoft Windows Vista
  • Microsoft Windows XP
  • Microsoft Windows Server 2003
Class:
vulnerability
Reference(s):
  • CVE-2010-2661
Product(s):
  • Opera Browser