Описание
Opera allows web sites to set cookies for country-specific top-level domains that have DNS A records, such as co.tv, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session, aka "Cross-Site Cooking."
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | DNE | removed from archive |
| devel | DNE | removed from archive |
| feisty | ignored | end of life, was needs-triage |
| gutsy | DNE | |
| hardy | DNE | removed from archive |
| intrepid | DNE | removed from archive |
| upstream | needs-triage |
Показывать по
Ссылки на источники
EPSS
6.8 Medium
CVSS2
Связанные уязвимости
Opera allows web sites to set cookies for country-specific top-level domains that have DNS A records, such as co.tv, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session, aka "Cross-Site Cooking."
Opera allows web sites to set cookies for country-specific top-level domains that have DNS A records, such as co.tv, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session, aka "Cross-Site Cooking."
EPSS
6.8 Medium
CVSS2