First published: Fri Oct 04 2002(Updated: )
Opera 6.0.1 and 6.0.2 allows a remote web site to upload arbitrary files from the client system, without prompting the client, via an input type=file tag whose value contains a newline.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opera Browser | =6.0.2 | |
Opera Browser | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0898 is considered a high severity vulnerability due to the potential for arbitrary file uploads.
To fix CVE-2002-0898, it is recommended to upgrade to a version of the Opera web browser that is not vulnerable, such as any version after 6.0.2.
CVE-2002-0898 can allow an attacker to upload malicious files to the victim's system without their consent, leading to data breaches.
CVE-2002-0898 affects Opera versions 6.0.1 and 6.0.2 on Windows.
While CVE-2002-0898 pertains to outdated software, it illustrates the importance of safeguarding browsers against file upload vulnerabilities.