Opera < 7.51 favicon.ico Address Bar Spoofing
Medium Nessus Plugin ID 14245
SynopsisThe remote host contains a web browser that is vulnerable to address bar spoofing attacks.
DescriptionThe version of Opera is vulnerable to a security weakness that may permit malicious web pages to spoof address bar information. It is reported that the 'favicon' feature can be used to spoof the domain of a malicious web page. An attacker can create an icon that includes the text of the desired site and is similar to the way Opera displays information in the address bar. The attacker can then obfuscate the real address with spaces.
This issue can be used to spoof information in the address bar, page bar and page/window cycler.
SolutionInstall to Opera 7.51 or newer.