CVE-2009-3266: XSS
Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to conduct cross-site scripting (XSS) attacks, and conduct cross-zone scripting attacks involving the Feed Subscription Page to read feeds or create feed subscriptions, via a crafted feed, related to the rendering of the application/rss+xml content type as "scripted content."
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3266?
CVE-2009-3266 has a high severity rating due to its potential for allowing remote cross-site scripting (XSS) attacks.
How do I fix CVE-2009-3266?
To fix CVE-2009-3266, upgrade to Opera version 10.01 or later, which addresses this vulnerability.
What are the consequences of CVE-2009-3266?
The consequences of CVE-2009-3266 include the ability for attackers to conduct XSS attacks and manipulate feed subscriptions.
Which versions of Opera are affected by CVE-2009-3266?
CVE-2009-3266 affects multiple versions of Opera prior to 10.01, including version 7.x and 9.x.
How does CVE-2009-3266 exploit work?
CVE-2009-3266 exploits the insufficient restriction of HTML in RSS and Atom feeds to execute malicious scripts.