// For flags

CVE-2009-2059

 

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Opera, possibly before 9.25, uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.

Opera, posiblemente anteriores a v9.25, utiliza una cabecera HTTP Host para determinar el contexto de un documento propocionado por una respuesta de CONEXIÓN (1) 4xx o (2) 5xx desde un servidor proxy, lo que permite a los atacantes "hombre en el medio" ejecutar arbitrariamente una secuencia de comandos web modificando la respuesta CONEXIÓN, también conocida como un ataque "forzado SSL".

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-06-15 CVE Reserved
  • 2009-06-15 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-17 EPSS Updated
  • 2024-09-17 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
<= 9.22
Search vendor "Opera" for product "Opera Browser" and version " <= 9.22"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.0
Search vendor "Opera" for product "Opera Browser" and version "7.0"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.23
Search vendor "Opera" for product "Opera Browser" and version "7.23"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.53
Search vendor "Opera" for product "Opera Browser" and version "7.53"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.54
Search vendor "Opera" for product "Opera Browser" and version "7.54"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.60
Search vendor "Opera" for product "Opera Browser" and version "7.60"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.0
Search vendor "Opera" for product "Opera Browser" and version "8.0"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.01
Search vendor "Opera" for product "Opera Browser" and version "8.01"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.02
Search vendor "Opera" for product "Opera Browser" and version "8.02"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.50
Search vendor "Opera" for product "Opera Browser" and version "8.50"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.51
Search vendor "Opera" for product "Opera Browser" and version "8.51"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.52
Search vendor "Opera" for product "Opera Browser" and version "8.52"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.53
Search vendor "Opera" for product "Opera Browser" and version "8.53"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.54
Search vendor "Opera" for product "Opera Browser" and version "8.54"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.0
Search vendor "Opera" for product "Opera Browser" and version "9.0"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.01
Search vendor "Opera" for product "Opera Browser" and version "9.01"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.02
Search vendor "Opera" for product "Opera Browser" and version "9.02"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.10
Search vendor "Opera" for product "Opera Browser" and version "9.10"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.12
Search vendor "Opera" for product "Opera Browser" and version "9.12"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.20
Search vendor "Opera" for product "Opera Browser" and version "9.20"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.21
Search vendor "Opera" for product "Opera Browser" and version "9.21"
-
Affected