if the location of the shell is:
http://www.victim.com/path/to/vt100.html;"><script>alert(1)</script>
Then when you call openPrinterWindow (defined in vt100.js) it will trigger an
XSS vulnerability.
The reason is because location.pathname doesn't escape double quotes in opera.
Original issue reported on code.google.com by evn@google.com on 12 Oct 2011 at 6:36
Original issue reported on code.google.com by
evn@google.com
on 12 Oct 2011 at 6:36