Vulnerability Name:

CVE-2002-0270 (CCN-45716)

Assigned:2002-02-12
Published:2002-02-12
Updated:2016-10-18
Summary:Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N)
2.1 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: BugTraq Mailing List, Tue Feb 12 2002 - 04:27:16 CST
geekgang Security Advisory [gsa2002-01]

Source: MITRE
Type: CNA
CVE-2002-0270

Source: BUGTRAQ
Type: UNKNOWN
20020212 [GSA2002-01] Web browsers ignore the Content-Type header, thus allowing cross-site scripting

Source: CCN
Type: Opera Web site
Opera browser

Source: CCN
Type: OSVDB ID: 57115
Opera MIME Content-Type Header Processing Weakness Cross-content XSS

Source: XF
Type: UNKNOWN
opera-contenttype-header-xss(45716)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:opera_software:opera_web_browser:9.10:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:opera:opera_browser:9.10:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    opera_software opera web browser 9.10
    opera opera browser 9.10