Vulnerability Details CVE-2009-2351
Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 10.00 Beta 3 Build 1699 is also affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.2%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2009-2351
-
cpe:2.3:a:opera:opera_browser:-
-
cpe:2.3:a:opera:opera_browser:1.00
-
cpe:2.3:a:opera:opera_browser:10.00
-
cpe:2.3:a:opera:opera_browser:2.00
-
cpe:2.3:a:opera:opera_browser:2.10
-
cpe:2.3:a:opera:opera_browser:2.12
-
cpe:2.3:a:opera:opera_browser:3.00
-
cpe:2.3:a:opera:opera_browser:3.10
-
cpe:2.3:a:opera:opera_browser:3.21
-
cpe:2.3:a:opera:opera_browser:3.50
-
cpe:2.3:a:opera:opera_browser:3.51
-
cpe:2.3:a:opera:opera_browser:3.60
-
cpe:2.3:a:opera:opera_browser:3.61
-
cpe:2.3:a:opera:opera_browser:3.62
-
cpe:2.3:a:opera:opera_browser:4.00
-
cpe:2.3:a:opera:opera_browser:4.01
-
cpe:2.3:a:opera:opera_browser:4.02
-
cpe:2.3:a:opera:opera_browser:5.0
-
cpe:2.3:a:opera:opera_browser:5.02
-
cpe:2.3:a:opera:opera_browser:5.10
-
cpe:2.3:a:opera:opera_browser:5.11
-
cpe:2.3:a:opera:opera_browser:5.12
-
cpe:2.3:a:opera:opera_browser:6.0
-
cpe:2.3:a:opera:opera_browser:6.01
-
cpe:2.3:a:opera:opera_browser:6.02
-
cpe:2.3:a:opera:opera_browser:6.03
-
cpe:2.3:a:opera:opera_browser:6.04
-
cpe:2.3:a:opera:opera_browser:6.05
-
cpe:2.3:a:opera:opera_browser:6.06
-
cpe:2.3:a:opera:opera_browser:6.1
-
cpe:2.3:a:opera:opera_browser:6.10
-
cpe:2.3:a:opera:opera_browser:6.11
-
cpe:2.3:a:opera:opera_browser:6.12
-
cpe:2.3:a:opera:opera_browser:7.0
-
cpe:2.3:a:opera:opera_browser:7.01
-
cpe:2.3:a:opera:opera_browser:7.02
-
cpe:2.3:a:opera:opera_browser:7.03
-
cpe:2.3:a:opera:opera_browser:7.10
-
cpe:2.3:a:opera:opera_browser:7.11
-
cpe:2.3:a:opera:opera_browser:7.20
-
cpe:2.3:a:opera:opera_browser:7.21
-
cpe:2.3:a:opera:opera_browser:7.22
-
cpe:2.3:a:opera:opera_browser:7.23
-
cpe:2.3:a:opera:opera_browser:7.30
-
cpe:2.3:a:opera:opera_browser:7.50
-
cpe:2.3:a:opera:opera_browser:7.51
-
cpe:2.3:a:opera:opera_browser:7.52
-
cpe:2.3:a:opera:opera_browser:7.53
-
cpe:2.3:a:opera:opera_browser:7.54
-
cpe:2.3:a:opera:opera_browser:7.55
-
cpe:2.3:a:opera:opera_browser:7.60
-
cpe:2.3:a:opera:opera_browser:8.0
-
cpe:2.3:a:opera:opera_browser:8.00
-
cpe:2.3:a:opera:opera_browser:8.01
-
cpe:2.3:a:opera:opera_browser:8.02
-
cpe:2.3:a:opera:opera_browser:8.50
-
cpe:2.3:a:opera:opera_browser:8.51
-
cpe:2.3:a:opera:opera_browser:8.52
-
cpe:2.3:a:opera:opera_browser:8.53
-
cpe:2.3:a:opera:opera_browser:8.54
-
cpe:2.3:a:opera:opera_browser:9.0
-
cpe:2.3:a:opera:opera_browser:9.00
-
cpe:2.3:a:opera:opera_browser:9.01
-
cpe:2.3:a:opera:opera_browser:9.02
-
cpe:2.3:a:opera:opera_browser:9.10
-
cpe:2.3:a:opera:opera_browser:9.12
-
cpe:2.3:a:opera:opera_browser:9.20
-
cpe:2.3:a:opera:opera_browser:9.21
-
cpe:2.3:a:opera:opera_browser:9.22
-
cpe:2.3:a:opera:opera_browser:9.23
-
cpe:2.3:a:opera:opera_browser:9.24
-
cpe:2.3:a:opera:opera_browser:9.25
-
cpe:2.3:a:opera:opera_browser:9.26
-
cpe:2.3:a:opera:opera_browser:9.27
-
cpe:2.3:a:opera:opera_browser:9.50
-
cpe:2.3:a:opera:opera_browser:9.51
-
cpe:2.3:a:opera:opera_browser:9.52