The XMLHttpRequest object in Opera 8.0 Final Build 1095 allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains via a redirect.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-1478
http://www.securityfocus.com/bid/13970