Error pages can be used to guess local file paths – Opera Security Advisories




Remote web pages should not be able to detect what files a user has on their local machine. Certain error pages do not apply this restriction correctly, allowing web pages to produce an error page where a script can run. The script can then use various events to detect whether files on the user’s computer exist or not.

Opera’s Response

Opera Software has released Opera 12.11, where this issue has been fixed.