{"api_version":"1","generated_at":"2026-04-24T22:08:35+00:00","cve":"CVE-2002-2358","urls":{"html":"https://cve.report/CVE-2002-2358","api":"https://cve.report/api/cve/CVE-2002-2358.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-2358","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-2358"},"summary":{"title":"CVE-2002-2358","description":"Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitrary web script or HTML via the title tag of an FTP URL.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.iss.net/security_center/static/9757.php","name":"http://www.iss.net/security_center/static/9757.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database: multiple-ftp-view-xss (9757): multiple vendor Web browser FTP view cross-site scripting","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0061.html","name":"http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0061.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://online.securityfocus.com/archive/1/286151","name":"http://online.securityfocus.com/archive/1/286151","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus HOME Mailing List: BugTraq","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/5401","name":"http://www.securityfocus.com/bid/5401","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"],"title":"Opera FTP View Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.opera.com/windows/changelogs/605/?session=b2a9ea38c710788c23970ba2c9a34d47","name":"http://www.opera.com/windows/changelogs/605/?session=b2a9ea38c710788c23970ba2c9a34d47","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Browsers for Windows, Mac, Linux | Web browsers for computers | Opera","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-2358","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-2358","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"2358","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opera_software","cpe5":"opera_web_browser","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"2358","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opera_software","cpe5":"opera_web_browser","cpe6":"6.0","cpe7":"*","cpe8":"win32","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"2358","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opera_software","cpe5":"opera_web_browser","cpe6":"6.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"2358","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opera_software","cpe5":"opera_web_browser","cpe6":"6.0.1","cpe7":"*","cpe8":"linux","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"2358","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opera_software","cpe5":"opera_web_browser","cpe6":"6.0.1","cpe7":"*","cpe8":"win32","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"2358","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opera_software","cpe5":"opera_web_browser","cpe6":"6.0.2","cpe7":"*","cpe8":"win32","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"2358","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opera_software","cpe5":"opera_web_browser","cpe6":"6.0.3","cpe7":"*","cpe8":"win32","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"2358","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opera_software","cpe5":"opera_web_browser","cpe6":"6.0.4","cpe7":"*","cpe8":"win32","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:59:11.872Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20020806 Opera FTP View Cross-Site Scripting Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://online.securityfocus.com/archive/1/286151"},{"name":"5401","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/5401"},{"name":"20020806 Opera FTP View Cross-Site Scripting Vulnerability","tags":["mailing-list","x_refsource_VULNWATCH","x_transferred"],"url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0061.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.opera.com/windows/changelogs/605/?session=b2a9ea38c710788c23970ba2c9a34d47"},{"name":"multiple-ftp-view-xss(9757)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/9757.php"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitrary web script or HTML via the title tag of an FTP URL."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-10-29T19:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20020806 Opera FTP View Cross-Site Scripting Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://online.securityfocus.com/archive/1/286151"},{"name":"5401","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/5401"},{"name":"20020806 Opera FTP View Cross-Site Scripting Vulnerability","tags":["mailing-list","x_refsource_VULNWATCH"],"url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0061.html"},{"tags":["x_refsource_MISC"],"url":"http://www.opera.com/windows/changelogs/605/?session=b2a9ea38c710788c23970ba2c9a34d47"},{"name":"multiple-ftp-view-xss(9757)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/9757.php"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-2358","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitrary web script or HTML via the title tag of an FTP URL."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20020806 Opera FTP View Cross-Site Scripting Vulnerability","refsource":"BUGTRAQ","url":"http://online.securityfocus.com/archive/1/286151"},{"name":"5401","refsource":"BID","url":"http://www.securityfocus.com/bid/5401"},{"name":"20020806 Opera FTP View Cross-Site Scripting Vulnerability","refsource":"VULNWATCH","url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0061.html"},{"name":"http://www.opera.com/windows/changelogs/605/?session=b2a9ea38c710788c23970ba2c9a34d47","refsource":"MISC","url":"http://www.opera.com/windows/changelogs/605/?session=b2a9ea38c710788c23970ba2c9a34d47"},{"name":"multiple-ftp-view-xss(9757)","refsource":"XF","url":"http://www.iss.net/security_center/static/9757.php"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-2358","datePublished":"2007-10-29T19:00:00.000Z","dateReserved":"2007-10-29T00:00:00.000Z","dateUpdated":"2024-09-16T21:56:59.153Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opera_software:opera_web_browser:6.0:*:*:*:*:*:*:*","matchCriteriaId":"0615E0B9-EFCF-4CDD-81E3-0E351DEB2C2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:opera_software:opera_web_browser:6.0:*:win32:*:*:*:*:*","matchCriteriaId":"041E7A50-D2D9-4469-88EA-D8D7CE5EC9C4"},{"vulnerable":true,"criteria":"cpe:2.3:a:opera_software:opera_web_browser:6.0.1:*:*:*:*:*:*:*","matchCriteriaId":"964BC1D9-10D2-4064-A0AD-5DD6E6A568E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:opera_software:opera_web_browser:6.0.1:*:linux:*:*:*:*:*","matchCriteriaId":"4DC0446A-9801-4AD9-ADE0-983E845E3A34"},{"vulnerable":true,"criteria":"cpe:2.3:a:opera_software:opera_web_browser:6.0.1:*:win32:*:*:*:*:*","matchCriteriaId":"25F0B4BE-F2B7-4774-8AAC-75239180D99B"},{"vulnerable":true,"criteria":"cpe:2.3:a:opera_software:opera_web_browser:6.0.2:*:win32:*:*:*:*:*","matchCriteriaId":"4B24013D-1E3D-4880-A9D6-C3F1ABED4FF9"},{"vulnerable":true,"criteria":"cpe:2.3:a:opera_software:opera_web_browser:6.0.3:*:win32:*:*:*:*:*","matchCriteriaId":"D9688B54-7A0D-4F8E-B2D8-D032A281C97A"},{"vulnerable":true,"criteria":"cpe:2.3:a:opera_software:opera_web_browser:6.0.4:*:win32:*:*:*:*:*","matchCriteriaId":"E32ECDB1-CD5E-4B2C-B064-F1A80C1995AE"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"2358","Ordinal":"1","Title":"CVE-2002-2358","CVE":"CVE-2002-2358","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"2358","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitrary web script or HTML via the title tag of an FTP URL.","Type":"Description","Title":"CVE-2002-2358"},{"CveYear":"2002","CveId":"2358","Ordinal":"2","NoteData":"2007-10-29","Type":"Other","Title":"Published"}]}}}