5
CVSSv2

CVE-2002-0898

Published: 04/10/2002 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Opera 6.0.1 and 6.0.2 allows a remote web site to upload arbitrary files from the client system, without prompting the client, via an input type=file tag whose value contains a newline.

Vulnerable Product Search on Vulmon Subscribe to Product

opera software opera web browser 6.0.1

opera software opera web browser 6.0.2

Exploits

source: wwwsecurityfocuscom/bid/4834/info A vulnerability has been reported in Opera 601/602 The vulnerability is related to handling of the 'file' HTML input-type It is possible for a server to set the file value, while fooling Opera into thinking no file has been specified This is possible if the filename is appended with the strin ...