Opera 9.10 Final allows remote attackers to bypass the Fraud Protection mechanism by adding certain characters to the end of a domain name, as demonstrated by the "." and "/" characters, which is not caught by the blacklist filter.
                
            References
                    Configurations
                    History
                    21 Nov 2024, 00:24
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://kaneda.bohater.net/security/20061220-opera_9.10_final_bypass_fraud_protection.php - Exploit, Vendor Advisory | |
| References | () http://osvdb.org/34927 - | |
| References | () http://www.securityfocus.com/archive/1/459265/100/0/threaded - | 
Information
                Published : 2007-02-07 11:28
Updated : 2025-04-09 00:30
NVD link : CVE-2006-6970
Mitre link : CVE-2006-6970
CVE.ORG link : CVE-2006-6970
JSON object : View
Products Affected
                opera
- opera_browser
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
