Lucene search

K
cveMitreCVE-2009-2351
HistoryJul 07, 2009 - 11:30 p.m.

CVE-2009-2351

2009-07-0723:30:00
CWE-79
mitre
web.nvd.nist.gov
32
opera
xss
javascript
uri
http
refresh headers
security vulnerability
cve-2009-2351

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.035

Percentile

91.6%

Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 10.00 Beta 3 Build 1699 is also affected.

Affected configurations

Nvd
Node
operaopera_browserRange9.52
OR
operaopera_browserMatch7.0
OR
operaopera_browserMatch7.23
OR
operaopera_browserMatch7.53
OR
operaopera_browserMatch7.54
OR
operaopera_browserMatch7.60
OR
operaopera_browserMatch8.0
OR
operaopera_browserMatch8.01
OR
operaopera_browserMatch8.02
OR
operaopera_browserMatch8.50
OR
operaopera_browserMatch8.51
OR
operaopera_browserMatch8.52
OR
operaopera_browserMatch8.53
OR
operaopera_browserMatch8.54
OR
operaopera_browserMatch9.0
OR
operaopera_browserMatch9.01
OR
operaopera_browserMatch9.02
OR
operaopera_browserMatch9.10
OR
operaopera_browserMatch9.12
OR
operaopera_browserMatch9.20
OR
operaopera_browserMatch9.21
OR
operaopera_browserMatch9.22
OR
operaopera_browserMatch9.51
OR
operaopera_browserMatch10.00beta_3
VendorProductVersionCPE
operaopera_browser*cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:*
operaopera_browser7.0cpe:2.3:a:opera:opera_browser:7.0:*:*:*:*:*:*:*
operaopera_browser7.23cpe:2.3:a:opera:opera_browser:7.23:*:*:*:*:*:*:*
operaopera_browser7.53cpe:2.3:a:opera:opera_browser:7.53:*:*:*:*:*:*:*
operaopera_browser7.54cpe:2.3:a:opera:opera_browser:7.54:*:*:*:*:*:*:*
operaopera_browser7.60cpe:2.3:a:opera:opera_browser:7.60:*:*:*:*:*:*:*
operaopera_browser8.0cpe:2.3:a:opera:opera_browser:8.0:*:*:*:*:*:*:*
operaopera_browser8.01cpe:2.3:a:opera:opera_browser:8.01:*:*:*:*:*:*:*
operaopera_browser8.02cpe:2.3:a:opera:opera_browser:8.02:*:*:*:*:*:*:*
operaopera_browser8.50cpe:2.3:a:opera:opera_browser:8.50:*:*:*:*:*:*:*
Rows per page:
1-10 of 241

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.035

Percentile

91.6%