Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2009-3013

Disclosure Date: August 31, 2009
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Opera 9.52 and earlier, and 10.00 Beta 3 Build 1699, does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header. NOTE: the JavaScript executes outside of the context of the HTTP site.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Vector:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown

General Information

Vendors

  • opera

Products

  • opera browser,
  • opera browser 10.00,
  • opera browser 7.0,
  • opera browser 7.23,
  • opera browser 7.53,
  • opera browser 7.54,
  • opera browser 7.60,
  • opera browser 8.0,
  • opera browser 8.01,
  • opera browser 8.02,
  • opera browser 8.50,
  • opera browser 8.51,
  • opera browser 8.52,
  • opera browser 8.53,
  • opera browser 8.54,
  • opera browser 9.0,
  • opera browser 9.01,
  • opera browser 9.02,
  • opera browser 9.10,
  • opera browser 9.12,
  • opera browser 9.20,
  • opera browser 9.21,
  • opera browser 9.22,
  • opera browser 9.51

Additional Info

Technical Analysis