CVE

Id
13612  
CVE No.
CVE-2005-2406  
Status
Candidate  
Description
Opera 8.01 allows remote attackers to conduct cross-site scripting (XSS) attacks or modify which files are uploaded by tricking a user into dragging an image that is a "javascript:" URI.  
Phase
Assigned (20050728)  
Votes
None (candidate not yet proposed)  
Comments