Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2002-0270

Quick assessment

Affected
n/a n/a
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Opera是一个商业化的浏览器产品,可运行于Windows及基于Linux的系统之下。 Opera 在处理页面中包含的Content-Type指令时存在漏洞,可能使远程恶意网站在浏览它的客户机上执行脚本。 当一个网页中包含有与其Content-Type 不符的标记时,Opera可能不会按照Content-Type中指定的类型进行处理。比如当一个Content-Type指定为text/plain的页面中包含有HTML标记时,Opera会把它作为HTML页面处理,这可能会导致在页面中的脚本程序被执行。

AI Predicted 6.1 Difficulty: Easy EPSS 4.73% · P92
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2002-0270

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Opera Content-Type HTML文件执行漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Opera是一个商业化的浏览器产品,可运行于Windows及基于Linux的系统之下。 Opera 在处理页面中包含的Content-Type指令时存在漏洞,可能使远程恶意网站在浏览它的客户机上执行脚本。 当一个网页中包含有与其Content-Type 不符的标记时,Opera可能不会按照Content-Type中指定的类型进行处理。比如当一个Content-Type指定为text/plain的页面中包含有HTML标记时,Opera会把它作为HTML页面处理,这可能会导致在页面中的脚本程序被执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2002-0270

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2002-0270

请登录查看更多情报信息。

Mailing List Discussions for CVE-2002-0270 (1)

Same Patch Batch · n/a · 2002-05-03 · 218 CVEs total

CVE-2002-0272 MPG321文件名ArgV缓冲区溢出漏洞
CVE-2002-0256 Arescom Net DSL 1000远程登录拒绝服务漏洞
CVE-2002-0257 MakeBid Auction Deluxe跨站脚本攻击(XSS)漏洞
CVE-2002-0258 IceWarp Web Mail会话ID泄露漏洞
CVE-2002-0259 InstantServers MiniPortal敏感文件纯文本存储漏洞
CVE-2002-0260 InstantServers MiniPortal FTP远程登录缓冲区溢出漏洞
CVE-2002-0261 InstantServers MiniPortal目录遍历漏洞
CVE-2002-0262 Sybex E-Trainer软件相关路径过滤目录遍历漏洞
CVE-2002-0263 EZNE.NET Ezboard 2000远程缓冲溢出漏洞
CVE-2002-0264 Cooolsoft PowerFTP Server纯文本账户信息漏洞
CVE-2002-0266 Thunderstone TEXIS路径泄露漏洞
CVE-2002-0268 Identix BioLogon GINA认证绕过漏洞
CVE-2002-0269 Microsoft Internet Explorer 安全漏洞
CVE-2002-0271 GNU Ada Compiler运行库泄露和临时文件创建漏洞
CVE-2002-0286 Sitenews未认证用户添加漏洞
CVE-2002-0283 Windows XP服务拒绝(CPU消耗)漏洞
CVE-2002-0284 Winamp路径名称泄露漏洞
CVE-2002-0285 Outlook Express的附件回车/换行密封过滤绕过漏洞
CVE-2002-0282 DCP-Portal WWW根目录绝对路径泄漏漏洞
CVE-2002-0288 Phusion Webserver目录遍历漏洞

Showing top 20 of 218 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2002-0270

No comments yet


Leave a comment