Opera 9.10 Final allows remote attackers to bypass the Fraud Protection mechanism by adding certain characters to the end of a domain name, as demonstrated by the "." and "/" characters, which is not caught by the blacklist filter.Referenceshttp://www.securityfocus.com/archive/1/459265/100/0/threadedhttp://osvdb.org/34927http://kaneda.bohater.net/security/20061220-opera_9.10_final_bypass_fraud_protection.php