CVE-2009-2059
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
15/06/2009
Last modified:
09/04/2025
Description
Opera, possibly before 9.25, uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:* | 9.22 (including) | |
cpe:2.3:a:opera:opera_browser:7.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:opera:opera_browser:7.23:*:*:*:*:*:*:* | ||
cpe:2.3:a:opera:opera_browser:7.53:*:*:*:*:*:*:* | ||
cpe:2.3:a:opera:opera_browser:7.54:*:*:*:*:*:*:* | ||
cpe:2.3:a:opera:opera_browser:7.60:*:*:*:*:*:*:* | ||
cpe:2.3:a:opera:opera_browser:8.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:opera:opera_browser:8.01:*:*:*:*:*:*:* | ||
cpe:2.3:a:opera:opera_browser:8.02:*:*:*:*:*:*:* | ||
cpe:2.3:a:opera:opera_browser:8.50:*:*:*:*:*:*:* | ||
cpe:2.3:a:opera:opera_browser:8.51:*:*:*:*:*:*:* | ||
cpe:2.3:a:opera:opera_browser:8.52:*:*:*:*:*:*:* | ||
cpe:2.3:a:opera:opera_browser:8.53:*:*:*:*:*:*:* | ||
cpe:2.3:a:opera:opera_browser:8.54:*:*:*:*:*:*:* | ||
cpe:2.3:a:opera:opera_browser:9.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page