CVE-2004-0872: Medium severity opera Opera Browser vulnerability

Published Sep 16, 2004
·
Updated

Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."

Affected Software

1 affected component
opera Opera Browser=7.51

Event History

Sep 16, 2004
CVE Published
04:00 AM
Feb 13, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2004-0872?

CVE-2004-0872 is considered a medium severity vulnerability due to the potential for cookie theft and unauthorized activities.

2

How do I fix CVE-2004-0872?

To mitigate CVE-2004-0872, ensure that cookies are marked with the Secure flag and transmitted only over secure channels.

3

What systems are affected by CVE-2004-0872?

CVE-2004-0872 affects Opera browser version 7.51.

4

What is the impact of CVE-2004-0872?

The impact of CVE-2004-0872 includes the potential for remote attackers to steal cookies, leading to unauthorized actions on behalf of users.

5

Is CVE-2004-0872 still a concern today?

While CVE-2004-0872 specifically affects an older version of the Opera browser, similar vulnerabilities can still be relevant, emphasizing the need for secure cookie handling in web applications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203