Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2004-2491 | First vendor Publication | 2004-12-31 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:H/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 2.6 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | High |
Cvss Expoit Score | 4.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing attacks. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2491 |
CAPEC : Common Attack Pattern Enumeration & Classification
Id | Name |
---|---|
CAPEC-26 | Leveraging Race Conditions |
CAPEC-29 | Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-362 | Race Condition |
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
8317 | Opera Multiple Function Address Bar Spoofing Opera contains a flaw that may allow a malicious user to spoof a trusted Web page. The issue is triggered when a remote attacker alters the opera address bar with the window.open and location.replace functions, which will load other page contents while keeping the URL. By crafting a specially-crafted web page, a remote attacker can spoof a trusted website to trick users into visiting a malicious Web site and possibly retrieve sensitive information, resulting in a loss of integrity. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-08-09 | Name : The remote host has application that may allow arbitrary code execution on th... File : opera_URI_obfuscation.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:22:46 |
|
2024-11-28 12:06:33 |
|
2022-03-02 01:01:56 |
|
2022-02-28 21:23:21 |
|
2021-05-04 12:02:38 |
|
2021-04-22 01:02:50 |
|
2020-05-23 00:16:11 |
|
2017-07-11 12:01:44 |
|
2016-06-28 15:11:55 |
|
2016-04-26 13:10:12 |
|
2014-02-17 10:29:27 |
|
2013-05-11 11:49:16 |
|