← Back

CVE-2009-3013

nvd nist
Published: Aug 31, 2009Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Opera 9.52 and earlier, and 10.00 Beta 3 Build 1699, does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header. NOTE: the JavaScript executes outside of the context of the HTTP site.

Affected (24)

Products: Opera: Opera Browser
1 product
Opera Browser
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Opera
Up to 9.52
Version 10.00 beta_3
Version 7.0
Version 7.23
Version 7.53
Version 7.54
Version 7.60
Version 8.01
Version 8.02
Version 8.0
Version 8.50
Version 8.51
Version 8.52
Version 8.53
Version 8.54
Version 9.01
Version 9.02
Version 9.0
Version 9.10
Version 9.12
Version 9.20
Version 9.21
Version 9.22
Version 9.51

References (6)

Source: cve@mitre.org
Exploit
Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.