Back

CVE-2005-1669

Cross-site scripting (XSS) vulnerability in Opera 8.0 Final Build 1095 allows remote attackers to inject arbitrary web script or HTML via "javascript:" URLs when a new window or frame is opened, which allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains.

Published: Jun 16, 2005 Modified: Jun 16, 2026
CWE-79

CVSS Metrics

Affected Products (1)

Vendor Product Version
opera opera_browser * < 8.01

GitHub Security Advisory GHSA-5pc8-2mqr-6q3h

Cross-site scripting (XSS) vulnerability in Opera 8.0 Final Build 1095 allows remote attackers to...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 1.85%

Top 23% most likely to be exploited

Threat Score 27.8 / 100

Data Sources

NVD EPSS GitHub