Loading
Generated remediation guidance and an executive summary. No account required.
Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks.
Use CWE-79, Opera Software vendor hub and Opera Web Browser product page to widen CVE-2002-0270 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2005-0233, CVE-2002-1091 and CVE-2002-0783 for nearby disclosures in the same product family.