« Volver al listado

CVE-2003-0593

Estado: ModificadaAlta (7.5)—

Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2003-0593",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2004-04-15T04:00:00.000",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html",
      "tags": [
        "Broken Link",
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html",
      "tags": [
        "Not Applicable"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html",
      "tags": [
        "Broken Link",
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html",
      "tags": [
        "Not Applicable"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Opera allows remote attackers to bypass intended cookie access restrictions on a web application via \"%2e%2e\" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application."
    },
    {
      "lang": "es",
      "value": "Opera permite a atacantes remotos saltarse las restriciones de cookies pretendidas en una aplicación web mediante secuencias de atravesamiento de directorios \"%2e%2e\" (punto punto codificado) en una URL, lo que hace que Opera envíe la cookie fuera de los subconjuntos de URL especificados, por ejemplo a una aplicación vulnerable que corre en el mismo servidor que la aplicación objetivo."
    }
  ],
  "lastModified": "2026-06-16T22:02:29.183",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CECFBC71-7814-4A24-A918-C593673727B4"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:5.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4F51D99-C77D-4DB6-8D4B-DF1CE9078543"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:5.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAA91E77-301C-48F6-9A57-D5FDCEF743BC"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:5.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C49DDEF-681C-4A34-9FF8-17249C42842D"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:5.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF365891-F3FA-4740-94B2-01F85254A2F9"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E42B4261-C511-4F3A-8596-6BD4E343DC31"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:6.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8D681B3-73E6-4257-84B4-DE83F6D659B3"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:6.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BF4EF8B-18CA-417C-BA30-024EE25B6AE8"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:6.03:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D9E5F2A5-F50F-4085-AB7D-8C91121A429A"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:6.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E90912E-0CF8-404B-9E86-461497C65A5A"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:6.05:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E19DD71-9447-4946-931F-4866537C8BC7"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:6.06:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "54075890-6E0C-4AB7-8BD5-2023419CC251"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:6.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "007C7237-022A-441E-80F1-B87E9F1D499E"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7C35850-B79C-4EE4-A6F2-CC5D2304724B"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50B797C8-3290-4278-9D4B-A15A14FB8D3A"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E10F658D-D2E4-4789-8172-F8842C3EEA05"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "55B110B5-ADE5-46AB-8BF1-AF61A0ECE5D8"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E7C6479D-4E40-4ED0-9A9D-9725CF3F0DB4"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.03:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81687D99-7444-4205-A7BE-992CC758675F"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D75C4301-68E9-4A10-B9C5-711252BF629B"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC690371-3326-421E-8BAC-14F48840671B"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6BE50982-8026-466C-9F51-867425C9986F"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.21:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B85C5F65-B814-4BF5-AB43-D0CFFE8175A0"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.22:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B0FAFA5-D27A-4F57-8B25-3E98DBF279A2"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.23:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8F6644C-97E6-4023-9C5C-5C1E1B0B55D7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}