VYPR
Unrated severityNVD Advisory· Published Aug 1, 2005· Updated Apr 16, 2026

CVE-2005-2406

CVE-2005-2406

Description

Opera 8.01 allows remote attackers to conduct cross-site scripting (XSS) attacks or modify which files are uploaded by tricking a user into dragging an image that is a "javascript:" URI.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.