Back
CVE-2004-1157
Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
Published: Jan 10, 2005
Modified: Jun 16, 2026
CWE-74
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| opera | opera_browser | * ≥ 7.0 |
GitHub Security Advisory GHSA-q8g3-xrmf-cprw
Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web...
References (8)
- http://secunia.com/advisories/13253/ Broken Link, Vendor Advisory
- http://secunia.com/multiple_browsers_window_injection_vulnerability_test/ Broken Link
- http://secunia.com/secunia_research/2004-13/advisory/ Broken Link
- http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml Third Party Advisory
- http://secunia.com/advisories/13253/ Broken Link, Vendor Advisory
- http://secunia.com/multiple_browsers_window_injection_vulnerability_test/ Broken Link
- http://secunia.com/secunia_research/2004-13/advisory/ Broken Link
- http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml Third Party Advisory
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
2.50%
Top 17% most likely to be exploited
Threat Score
30.7 / 100
Data Sources
NVD
EPSS
GitHub