Opera’s status bar shows the “title” attribute of a form inputimage, not the form’s “action” URL. This may mislead the user.
Severity: Very low
It is possible to make a form input that looks like an image link.If the form input has a “title” attribute, the status bar will showthe “title”. A “title” which looks like a URL can mislead the user,since the title can say http://nice.familiar.com/, while the formaction can be something else.
Opera’s tooltip says “Title:” before the title text, making a spoofURL less convincing. A user who has enabled the status bar anddisabled tooltips can be affected by this. Neither of these settingsare Opera’s defaults.
Opera has released version 8.52, which displays the form action URL in the status bar,and both the “title” and the action URL in the tooltip.
Thanks to Secunia for pointing out how the “title” attributecould be abused to trick the user.