CVE-2003-0593 Details
Description
Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html | CVE | Broken LinkExploitVendor Advisory |
| http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html | CVE | Not Applicable |
| http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html | [email protected] | Broken LinkExploitVendor Advisory |
| http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html | [email protected] | Not Applicable |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| opera opera browser | 5.0 5.02 5.10 5.11 5.12 6.0 6.01 6.02 6.03 6.04 6.05 6.06 6.10 7.0 7.0 beta1 7.0 beta2 7.01 7.02 7.03 7.10 7.11 7.20 7.21 7.22 7.23 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Apr 16, 2026 | [email protected] | |
| Nov 20, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Mar 1, 2022 | Reanalysis | [email protected] |
| Jan 1, 2004 | Initial Analysis | [email protected] |