Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript to read arbitrary files from the client's local filesystem or display a false URL to the user.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-2561
http://www.securityfocus.com/bid/10873
http://www.opera.com/docs/changelogs/windows/754/
http://www.greymagic.com/security/advisories/gm008-op/
http://secunia.com/advisories/12233
http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0131.html