Opera 7.54 and earlier allows remote attackers to spoof file types in the download dialog via dots and non-breaking spaces (ASCII character code 160) in the (1) Content-Disposition or (2) Content-Type headers.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Opera_browser | Opera | * | 7.54 (including) |