« Volver al listado

CVE-2009-3013

Estado: ModificadaMedia (4.3)—

Opera 9.52 and earlier, and 10.00 Beta 3 Build 1699, does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header. NOTE: the JavaScript executes outside of the context of the HTTP site.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-3013",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-08-31T16:30:06.937",
  "references": [
    {
      "url": "http://websecurity.com.ua/3323/",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://websecurity.com.ua/3386/",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52996",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://websecurity.com.ua/3323/",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://websecurity.com.ua/3386/",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52996",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Opera 9.52 and earlier, and 10.00 Beta 3 Build 1699, does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header.  NOTE: the JavaScript executes outside of the context of the HTTP site."
    },
    {
      "lang": "es",
      "value": "Opera v9.52 y anteriores, y 10.00 Beta 3 Build 1699, no bloquea apropiadamente las URIs data: en las cabeceras Location en las respuestas HTTP, lo que permite realizar, a atacantes remotos, ataques de ejecución de secuencias de comandos en sitios cruzados(XSS) a través de vectores relacionados con (1) la inyección de una cabecera Location contiene secuencias de JavaScript en una URI data:text/html o (2) intrducción de una URI data:text/html con secuencias de JavaScript cuando se especifica el contenido de una cabecera Location. NOTA: el código JavaScript se ejecuta fuera del contexto del sitio HTTP."
    }
  ],
  "lastModified": "2026-06-16T23:10:43.497",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC7CF5F1-7CB8-4E77-8462-CE1BF0591D58",
              "versionEndIncluding": "9.52"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7C35850-B79C-4EE4-A6F2-CC5D2304724B"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.23:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8F6644C-97E6-4023-9C5C-5C1E1B0B55D7"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.53:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7965089-8592-47F2-958B-7DBE669BCAC9"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.54:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1750B2D-7AC8-45CF-9879-1D0476EEE86C"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.60:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECEE4473-88C0-4E28-A5B5-F7383B0E5558"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76410AD4-78CA-48EA-83F0-099D0A49626F"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DF2B21F-7E97-416B-AF5C-35338A254552"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DBAC41D6-73D4-44E9-87E4-E1E955B9580A"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.50:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52FCCB1C-165C-49FF-B70B-475B37BDF02A"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.51:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FA5A5E5-3703-44AC-9963-A20A55002B48"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.52:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC3E5BEF-3F29-4929-A37C-C49322B19047"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.53:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B0E7B5D-2568-4128-8F99-E74D24A7E991"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.54:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6A04906-7267-4A09-87BF-D639C7CF315B"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BEA17D3F-A17B-47A6-8066-583F63D11468"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED63C1B5-F52D-4C70-82D3-B427EAF5CF4F"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98E48C83-01AE-4A33-A004-14B99792674C"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B56A2B78-70BD-439B-B1ED-A17FA5EF0990"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "623E4466-82CC-4BDD-BE25-3BB33B585547"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F90E537-5A0F-4302-9CC3-8EE7EB21DD1D"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.21:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5ECA190-D7D3-4248-A61E-0D87E67E3D31"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.22:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8FD514B3-AFCD-4CB1-9D1B-18625B771E0A"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.51:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CAC4250E-E638-4015-B5EF-7B5405F7FBFC"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:10.00:beta_3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABB6D630-28EC-4506-AD0D-8C9A5E7D45CB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}