CVE
- Id
- 4662
- CVE No.
- CVE-2002-0270
- Status
- Candidate
- Description
- Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks.
- Phase
- Proposed (20020502)
- Votes
- MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | REJECT(1) Armstrong
- Comments
- Frech> XF:ie-opera-contenttype-css(8218) | Christey> BID:4098 | URL:http://www.securityfocus.com/bid/4098