Opera 8.01 allows remote attackers to conduct cross-site scripting (XSS) attacks or modify which files are uploaded by tricking a user into dragging an image that is a "javascript:" URI.Referenceshttp://www.opera.com/linux/changelogs/802/http://www.vupen.com/english/advisories/2005/1251http://www.securityfocus.com/bid/14410http://securitytracker.com/id?1014593http://secunia.com/advisories/15756