// For flags

CVE-2009-3013

 

Severity Score

6.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Opera 9.52 and earlier, and 10.00 Beta 3 Build 1699, does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header. NOTE: the JavaScript executes outside of the context of the HTTP site.

Opera v9.52 y anteriores, y 10.00 Beta 3 Build 1699, no bloquea apropiadamente las URIs data: en las cabeceras Location en las respuestas HTTP, lo que permite realizar, a atacantes remotos, ataques de ejecución de secuencias de comandos en sitios cruzados(XSS) a través de vectores relacionados con (1) la inyección de una cabecera Location contiene secuencias de JavaScript en una URI data:text/html o (2) intrducción de una URI data:text/html con secuencias de JavaScript cuando se especifica el contenido de una cabecera Location. NOTA: el código JavaScript se ejecuta fuera del contexto del sitio HTTP.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-08-31 CVE Reserved
  • 2009-08-31 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
<= 9.52
Search vendor "Opera" for product "Opera Browser" and version " <= 9.52"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.0
Search vendor "Opera" for product "Opera Browser" and version "7.0"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.23
Search vendor "Opera" for product "Opera Browser" and version "7.23"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.53
Search vendor "Opera" for product "Opera Browser" and version "7.53"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.54
Search vendor "Opera" for product "Opera Browser" and version "7.54"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
7.60
Search vendor "Opera" for product "Opera Browser" and version "7.60"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.0
Search vendor "Opera" for product "Opera Browser" and version "8.0"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.01
Search vendor "Opera" for product "Opera Browser" and version "8.01"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.02
Search vendor "Opera" for product "Opera Browser" and version "8.02"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.50
Search vendor "Opera" for product "Opera Browser" and version "8.50"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.51
Search vendor "Opera" for product "Opera Browser" and version "8.51"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.52
Search vendor "Opera" for product "Opera Browser" and version "8.52"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.53
Search vendor "Opera" for product "Opera Browser" and version "8.53"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
8.54
Search vendor "Opera" for product "Opera Browser" and version "8.54"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.0
Search vendor "Opera" for product "Opera Browser" and version "9.0"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.01
Search vendor "Opera" for product "Opera Browser" and version "9.01"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.02
Search vendor "Opera" for product "Opera Browser" and version "9.02"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.10
Search vendor "Opera" for product "Opera Browser" and version "9.10"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.12
Search vendor "Opera" for product "Opera Browser" and version "9.12"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.20
Search vendor "Opera" for product "Opera Browser" and version "9.20"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.21
Search vendor "Opera" for product "Opera Browser" and version "9.21"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.22
Search vendor "Opera" for product "Opera Browser" and version "9.22"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
9.51
Search vendor "Opera" for product "Opera Browser" and version "9.51"
-
Affected
Opera
Search vendor "Opera"
Opera Browser
Search vendor "Opera" for product "Opera Browser"
10.00
Search vendor "Opera" for product "Opera Browser" and version "10.00"
beta_3
Affected