CVE-2002-0270
Last modified
CVE-2002-0270 is a vulnerability of currently unknown severity. Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks.. EPSS estimates a 4.73% chance of exploitation in the next 30 days.
Description
Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opera Software | Opera Web Browser | 9.10 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0270?
How severe is CVE-2002-0270?
How do I fix CVE-2002-0270?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2002
- CVE-2002-0264PowerFTP Personal FTP Server 2.03 through 2.10 stores sensit…
- CVE-2002-0265Sawmill for Solaris 6.2.14 and earlier creates the AdminPass…
- CVE-2002-0266Thunderstone Texis CGI script allows remote attackers to obt…
- CVE-2002-0267preferences.php in Simple Internet Publishing System (SIPS) …
- CVE-2002-0268Identix BioLogon 3 allows users with physical access to the …
- CVE-2002-0269Internet Explorer 5.x and 6 interprets an object as an HTML …
- CVE-2002-0271Runtime library in GNU Ada compiler (GNAT) 3.12p through 3.1…
- CVE-2002-0272Buffer overflows in mpg321 before 0.2.9 allows local and pos…
- CVE-2002-0273Buffer overflow in CWMail.exe in NetWin before 2.8a allows r…
- CVE-2002-0274Exim 3.34 and earlier may allow local users to gain privileg…
- CVE-2002-0275Falcon web server 2.0.0.1020 and earlier allows remote attac…
- CVE-2002-0276Buffer overflow in various decoders in Ettercap 0.6.3.1 and …
Are you affected by CVE-2002-0270?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
