← Back

CVE-2003-0593

nvd nist
Published: Apr 15, 2004Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

Affected (25)

Products: Opera: Opera Browser
1 product
Opera Browser
Configuration A
25 vulnerable
Vulnerable SoftwareAffected Versions
Opera
Version 5.02
Version 5.0
Version 5.10
Version 5.11
Version 5.12
Version 6.01
Version 6.02
Version 6.03
Version 6.04
Version 6.05
Version 6.06
Version 6.0
Version 6.10
Version 7.01
Version 7.02
Version 7.03
Version 7.0
Version 7.0 beta1
Version 7.0 beta2
Version 7.10
Version 7.11
Version 7.20
Version 7.21
Version 7.22
Version 7.23

References (4)

Source: cve@mitre.org
Broken LinkExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable

Timeline

No history available yet.