CVE-2001-0898 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 3.1% (pctl 87)
Patch early
A public exploit exists.
Description
Opera 6.0 and earlier allows remote attackers to access sensitive information such as cookies and links for other domains via Javascript that uses setTimeout to (1) access data after a new window to the domain has been opened or (2) access data via about:cache.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 3.09% — more likely to be exploited than 87% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2001-11-15 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| opera software | opera web browser |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Opera 5.0/5.1 - Same Origin Policy Circumvention | 2001-11-15 |
References
- http://marc.info/?l=bugtraq&m=100586079932284&w=2
- http://marc.info/?l=bugtraq&m=100588139312696&w=2
- http://www.iss.net/security_center/static/7567.php
- http://www.securityfocus.com/bid/3553
- http://marc.info/?l=bugtraq&m=100586079932284&w=2
- http://marc.info/?l=bugtraq&m=100588139312696&w=2
- http://www.iss.net/security_center/static/7567.php
- http://www.securityfocus.com/bid/3553
→ the Explorer · watch your stack · NVD