// For flags

CVE-2009-2351

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 10.00 Beta 3 Build 1699 is also affected.

El navegador Opera versión 9.52 y versiones anteriores no bloquean javascript: URI en los encabezados de actualización en las respuestas HTTP, lo que permite a los atacantes remotos conducir ataques de tipo Cross-Site Scripting (XSS) mediante vectores relacionados con (1) inyectar un encabezado Refresh o (2) especificar el contenido de un encabezado Refresh, un problema relacionado con CVE-2009-1312. NOTA: luego se informó que 10.00 Beta 3 Build 1699 también se ve afectado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-07-07 CVE Reserved
  • 2009-07-07 CVE Published
  • 2023-10-10 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
<= 9.52
Search vendor "Opera" for product "Opera Browser" and version " <= 9.52"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.0
Search vendor "Opera" for product "Opera Browser" and version "7.0"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.23
Search vendor "Opera" for product "Opera Browser" and version "7.23"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.53
Search vendor "Opera" for product "Opera Browser" and version "7.53"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.54
Search vendor "Opera" for product "Opera Browser" and version "7.54"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.60
Search vendor "Opera" for product "Opera Browser" and version "7.60"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.0
Search vendor "Opera" for product "Opera Browser" and version "8.0"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.01
Search vendor "Opera" for product "Opera Browser" and version "8.01"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.02
Search vendor "Opera" for product "Opera Browser" and version "8.02"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.50
Search vendor "Opera" for product "Opera Browser" and version "8.50"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.51
Search vendor "Opera" for product "Opera Browser" and version "8.51"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.52
Search vendor "Opera" for product "Opera Browser" and version "8.52"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.53
Search vendor "Opera" for product "Opera Browser" and version "8.53"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.54
Search vendor "Opera" for product "Opera Browser" and version "8.54"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.0
Search vendor "Opera" for product "Opera Browser" and version "9.0"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.01
Search vendor "Opera" for product "Opera Browser" and version "9.01"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.02
Search vendor "Opera" for product "Opera Browser" and version "9.02"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.10
Search vendor "Opera" for product "Opera Browser" and version "9.10"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.12
Search vendor "Opera" for product "Opera Browser" and version "9.12"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.20
Search vendor "Opera" for product "Opera Browser" and version "9.20"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.21
Search vendor "Opera" for product "Opera Browser" and version "9.21"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.22
Search vendor "Opera" for product "Opera Browser" and version "9.22"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.51
Search vendor "Opera" for product "Opera Browser" and version "9.51"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
10.00
Search vendor "Opera" for product "Opera Browser" and version "10.00"
beta_3
Affected