VulnerabilityModified
CVE-2003-1420
Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with automatic redirection disabled allows remote attackers to inject arbitrary web script or HTML via the HTTP Location header.
MEDIUM 4.3EPSS 2.00%
Does this matter?
Lower severity and a low EPSS score (2.00%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with automatic redirection disabled allows remote attackers to inject arbitrary web script or HTML via the HTTP Location header.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.00% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- opera/opera browser
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/313216Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/6962Broken Link, Patch, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11423Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/313216Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/6962Broken Link, Patch, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11423Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.