Lucene search

K
cvelistMitreCVELIST:CVE-2011-4681
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2011-4681

2022-10-0316:15:13
mitre
www.cve.org
7
opera
same origin policy
bypass
domain names
remote attackers

AI Score

7.4

Confidence

High

EPSS

0.002

Percentile

58.7%

Opera before 11.60 does not properly consider the number of . (dot) characters that conventionally exist in domain names of different top-level domains, which allows remote attackers to bypass the Same Origin Policy by leveraging access to a different domain name in the same top-level domain, as demonstrated by the .no or .uk domain.

AI Score

7.4

Confidence

High

EPSS

0.002

Percentile

58.7%

Related for CVELIST:CVE-2011-4681