CVE-2004-0872: Medium severity opera Opera Browser vulnerability
Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0872?
CVE-2004-0872 is considered a medium severity vulnerability due to the potential for cookie theft and unauthorized activities.
How do I fix CVE-2004-0872?
To mitigate CVE-2004-0872, ensure that cookies are marked with the Secure flag and transmitted only over secure channels.
What systems are affected by CVE-2004-0872?
CVE-2004-0872 affects Opera browser version 7.51.
What is the impact of CVE-2004-0872?
The impact of CVE-2004-0872 includes the potential for remote attackers to steal cookies, leading to unauthorized actions on behalf of users.
Is CVE-2004-0872 still a concern today?
While CVE-2004-0872 specifically affects an older version of the Opera browser, similar vulnerabilities can still be relevant, emphasizing the need for secure cookie handling in web applications.