CVE-2009-2059

Opera < 9.25 - Cross-Site Scripting via Proxy CONNECT Response

Title source: llm
STIX 2.1

Description

Opera, possibly before 9.25, uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.

References (2)

Core 2

Scores

EPSS 0.0024
EPSS Percentile 46.3%

Details

CWE
CWE-287
Status published
Products (21)
opera/opera_browser 7.0
opera/opera_browser 7.23
opera/opera_browser 7.53
opera/opera_browser 7.54
opera/opera_browser 7.60
opera/opera_browser 8.0
opera/opera_browser 8.01
opera/opera_browser 8.02
opera/opera_browser 8.50
opera/opera_browser 8.51
... and 11 more
Published Jun 15, 2009
Tracked Since Feb 18, 2026