CVE-2009-2351

CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.41 % (74th)
0.41% Progress
Affected Products 1

Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 10.00 Beta 3 Build 1699 is also affected.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Related CVEs
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2009-07-07 23:30:00
(15 years ago)
Updated Date
2018-10-30 16:26:33
(5 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Opera Browser 9.52 and prior versions cpe:2.3:a:opera:opera_browser <= 9.52
  Opera Browser 7.0 cpe:2.3:a:opera:opera_browser:7.0
  Opera Browser 7.23 cpe:2.3:a:opera:opera_browser:7.23
  Opera Browser 7.53 cpe:2.3:a:opera:opera_browser:7.53
  Opera Browser 7.54 cpe:2.3:a:opera:opera_browser:7.54
  Opera Browser 7.60 cpe:2.3:a:opera:opera_browser:7.60
  Opera Browser 8.0 cpe:2.3:a:opera:opera_browser:8.0
  Opera Browser 8.01 cpe:2.3:a:opera:opera_browser:8.01
  Opera Browser 8.02 cpe:2.3:a:opera:opera_browser:8.02
  Opera Browser 8.50 cpe:2.3:a:opera:opera_browser:8.50
  Opera Browser 8.51 cpe:2.3:a:opera:opera_browser:8.51
  Opera Browser 8.52 cpe:2.3:a:opera:opera_browser:8.52
  Opera Browser 8.53 cpe:2.3:a:opera:opera_browser:8.53
  Opera Browser 8.54 cpe:2.3:a:opera:opera_browser:8.54
  Opera Browser 9.0 cpe:2.3:a:opera:opera_browser:9.0
  Opera Browser 9.01 cpe:2.3:a:opera:opera_browser:9.01
  Opera Browser 9.02 cpe:2.3:a:opera:opera_browser:9.02
  Opera Browser 9.10 cpe:2.3:a:opera:opera_browser:9.10
  Opera Browser 9.12 cpe:2.3:a:opera:opera_browser:9.12
  Opera Browser 9.20 cpe:2.3:a:opera:opera_browser:9.20
  Opera Browser 9.21 cpe:2.3:a:opera:opera_browser:9.21
  Opera Browser 9.22 cpe:2.3:a:opera:opera_browser:9.22
  Opera Browser 9.51 cpe:2.3:a:opera:opera_browser:9.51
  Opera Browser 10.00 Beta 3 cpe:2.3:a:opera:opera_browser:10.00:beta_3
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...