| Vulnerability Name: | CCN-17015 | ||||||
| Published: | 2004-08-17 | ||||||
| Updated: | 2004-08-17 | ||||||
| Summary: | Opera could allow a remote attacker to obtain sensitive information. By creating a specially-crafted Web page that references a file or directory within an IFRAME, a remote attacker could determine the existence of a file or directory depending on if an error is returned, once the malicious Web page is visited. An attacker can then use this information to launch further attacks against the affected system. | ||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||
| CVSS v2 Severity: | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||
| Vulnerability Consequences: | Obtain Information | ||||||
| References: | Source: CCN Type: VulnWatch Mailing List, Tue Aug 17 2004 - 07:50:30 CDT Opera Local File/Directory Detection (GM#009-OP) Source: CCN Type: BID-10961 Opera Web Browser Resource Detection Weakness Source: XF Type: UNKNOWN opera-iframe-info-disclosure(17015) | ||||||
| Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
| BACK | |||||||