Executive Summary
This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations | |||
---|---|---|---|
Name | CVE-2004-2260 | First vendor Publication | 2004-12-31 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Opera Browser 7.23, and other versions before 7.50, updates the address bar as soon as the user clicks a link, which allows remote attackers to redirect to other sites via the onUnload attribute. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2260 |
CAPEC : Common Attack Pattern Enumeration & Classification
Id | Name |
---|---|
CAPEC-26 | Leveraging Race Conditions |
CAPEC-29 | Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') (CWE/SANS Top 25) |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2005-11-03 | Name : Opera web browser address bar spoofing weakness File : nvt/opera_address_bar_spoofing.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
6108 | Opera onUnload Address Bar Spoofing Opera contains a flaw that may allow a malicious user to disguise the location of a web page. The issue is triggered when the onUnload body attribute is used to change the address bar information without leaving the current page. It is possible that the flaw may allow malicious web site operators to misrepresent their content as someone else's, resulting in a loss of integrity. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-08-10 | Name : An installed browser is vulnerable to address bar spoofing. File : opera_address_bar_spoofing.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:22:43 |
|
2024-11-28 12:06:30 |
|
2022-03-02 01:01:55 |
|
2022-02-28 21:23:21 |
|
2021-05-04 12:02:36 |
|
2021-04-22 01:02:48 |
|
2020-05-23 00:16:09 |
|
2017-07-11 12:01:43 |
|
2016-06-28 15:10:26 |
|
2016-04-26 13:07:50 |
|
2014-02-17 10:29:22 |
|
2013-05-11 11:47:59 |
|