// For flags

CVE-2009-2351

 

Severity Score

6.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 10.00 Beta 3 Build 1699 is also affected.

El navegador Opera versión 9.52 y versiones anteriores no bloquean javascript: URI en los encabezados de actualización en las respuestas HTTP, lo que permite a los atacantes remotos conducir ataques de tipo Cross-Site Scripting (XSS) mediante vectores relacionados con (1) inyectar un encabezado Refresh o (2) especificar el contenido de un encabezado Refresh, un problema relacionado con CVE-2009-1312. NOTA: luego se informó que 10.00 Beta 3 Build 1699 también se ve afectado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-07-07 CVE Reserved
  • 2009-07-07 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
<= 9.52
Search vendor "Opera" for product "Opera Browser" and version " <= 9.52"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.0
Search vendor "Opera" for product "Opera Browser" and version "7.0"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.23
Search vendor "Opera" for product "Opera Browser" and version "7.23"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.53
Search vendor "Opera" for product "Opera Browser" and version "7.53"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.54
Search vendor "Opera" for product "Opera Browser" and version "7.54"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.60
Search vendor "Opera" for product "Opera Browser" and version "7.60"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.0
Search vendor "Opera" for product "Opera Browser" and version "8.0"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.01
Search vendor "Opera" for product "Opera Browser" and version "8.01"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.02
Search vendor "Opera" for product "Opera Browser" and version "8.02"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.50
Search vendor "Opera" for product "Opera Browser" and version "8.50"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.51
Search vendor "Opera" for product "Opera Browser" and version "8.51"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.52
Search vendor "Opera" for product "Opera Browser" and version "8.52"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.53
Search vendor "Opera" for product "Opera Browser" and version "8.53"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.54
Search vendor "Opera" for product "Opera Browser" and version "8.54"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.0
Search vendor "Opera" for product "Opera Browser" and version "9.0"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.01
Search vendor "Opera" for product "Opera Browser" and version "9.01"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.02
Search vendor "Opera" for product "Opera Browser" and version "9.02"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.10
Search vendor "Opera" for product "Opera Browser" and version "9.10"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.12
Search vendor "Opera" for product "Opera Browser" and version "9.12"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.20
Search vendor "Opera" for product "Opera Browser" and version "9.20"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.21
Search vendor "Opera" for product "Opera Browser" and version "9.21"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.22
Search vendor "Opera" for product "Opera Browser" and version "9.22"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.51
Search vendor "Opera" for product "Opera Browser" and version "9.51"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
10.00
Search vendor "Opera" for product "Opera Browser" and version "10.00"
beta_3
Affected