Web Hack List

Other nomination

Hijacking Opera's Native Page using malicious RSS payloads

Untrusted RSS feed content is rendered in Opera's Feed Subscription Page, a native page running in a higher-privileged zone than the internet zone. Escaping that page's HTML tag whitelist and sanitiser lets a crafted feed run script there and call native functions such as opera.feeds.subscribeNative, taking control of the browser. Fixed in Opera 10.01.

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.