Opera Content-Type HTML File Execution Vulnerability

Homer

Well-known member
Opera is a commercial web browser product, and is available for Windows and Linux based systems.

Opera does not properly handle files based on the Content-Type specified. If HTML tags are included in the body of a file, Opera will not handle the file according to the Content-Type. For example: A file has the Content-Type text/plain and contains HTML tags in the file, Opera will execute the file as a HTML type rather than a text file.

It is possible to create a malicious web page containing arbitrary script code. When a legitimate user browses the malicious page, the script code could be executed in the user's browser.
 
Top