MEDIUM
Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312
Published Jul 7, 2009
4.3
MEDIUMCVSS 2.0
EPSS 1.71%
Description
Affected products
Remediation
References (5)
Change history (0)
No recorded changes yet.