CVE-2009-3048: Input Validation
Opera before 10.00 on Linux, Solaris, and FreeBSD does not properly implement the "INPUT TYPE=file" functionality, which allows remote attackers to trick a user into uploading an unintended file via vectors involving a "dropped file."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3048?
CVE-2009-3048 is classified as a medium severity vulnerability that affects multiple versions of the Opera browser.
How do I fix CVE-2009-3048?
To fix CVE-2009-3048, users should update their Opera browser to the latest version available.
What does CVE-2009-3048 allow attackers to do?
CVE-2009-3048 allows attackers to trick users into uploading unintended files through the browser's file input functionality.
Which operating systems are affected by CVE-2009-3048?
CVE-2009-3048 affects Opera versions prior to 10.00 on Linux, Solaris, and FreeBSD systems.
Is there a patch available for CVE-2009-3048?
Yes, a patch is available and applying it involves upgrading to Opera version 10.00 or later.