Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obtain sensitive information by leveraging control of a different web site in the same top-level domain.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2013-04-19T10:00:00Z

Updated: 2024-09-16T23:15:57.128Z

Reserved: 2013-04-19T00:00:00Z

Link: CVE-2013-3210

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2013-04-19T11:44:29.787

Modified: 2024-11-21T01:53:11.080

Link: CVE-2013-3210

cve-icon Redhat

No data.