Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-53rf-2cq9-qrrj

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

EPSS

Процентиль: 36%
0.00146
Низкий

Дефекты

CWE-22

Связанные уязвимости

nvd
больше 21 года назад

Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

EPSS

Процентиль: 36%
0.00146
Низкий

Дефекты

CWE-22