Collected research
Pwning Opera Unite with Inferno's Eleven
Pwning Opera Unite with Inferno’s Eleven
Eleven flaws in the Opera Unite 10 beta, tested against Build 1703. Username and computer-name enumeration, service-owner IP and port disclosure, plain-HTTP service pages, phishing hosted on trusted operaunite.com, CSRF file upload yielding stored XSS that steals the ACL password, CSRF against the Fridge and chatroom, cookie XSS via Flash header forging, and weak default passwords.
Record
- Document
- Pwning Opera Unite with Inferno’s Eleven
- Researcher
- Inferno
- Published by
- securethoughts.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Inferno, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .