Search the knowledge base

JavaScript errors can scrape limited information from unrelated sites

Severity

Low

Description

Loading a non-JavaScript file as a script will typically cause the browser to ignore the file, as it cannot be interpreted as JavaScript. The content of that file will not be available to scripts. In some cases, files containing specifically formatted contents may be interpreted as a JavaScript that throws an error. This type of error may be intercepted by the page, allowing one word to be read. In rare cases, this may leak confidential information to unrelated sites, such as an identification token for logged-in users.

Opera's Response

Opera Software has released Opera 11.10, where this issue has been fixed.

Credits

Thanks to Daniel Divricean of divricean.ro for reporting this issue to Opera Software.


Browse through articles in the same categories: advisory

Support

Opera Help

Need help? Hit F1 anytime while using Opera to access our online help files, or go here.