CNCVE编号:CNCVE-20020061 CVE编号: 安全级别:高 漏洞中文描述: Opera是一个商业化的浏览器产品,可运行于Windows及基于Linux的系统之下。Opera 在处理页面中包含的Content-Type指令时存在漏洞,可能使远程恶意网站在浏览它的客户机上执行脚本。当一个网页中包含有与其Content-Type 不符的标记时,Opera可能不会按照Content-Type中指定的类型进行处理。比如当一个Content-Type指定为text/plain的页面中包含有HTML标记时,Opera会把它作为HTML页面处理,这可能会导致在页面中的脚本程序被执行。 漏洞英文描述: Opera is a commercial web browser product, and is available for Windows and Linux based systems. Opera does not properly handle files based on the Content-Type specified. If HTML tags are included in the body of a file, Opera will not handle the file according to the Content-Type. For example: A file has the Content-Type text/plain and contains HTML tags in the file, Opera will execute the file as a HTML type rather than a text file. It is possible to create a malicious web page containing arbitrary script code. When a legitimate user browses the malicious page, the script code could be executed in the user's browser. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0130.html 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误