[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-0820Date: (C)2004-08-28   (M)2023-12-22


Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are referenced from XML files contained in a .wsz skin file.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.6
Exploit Score: 3.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECUNIA-12381
ESB-2004.0537
http://www.frsirt.com/exploits/08252004.skinhead.php
winamp-wsz-execute-code(17124)

CPE    6
cpe:/a:nullsoft:winamp:2.91
cpe:/a:nullsoft:winamp:5.01
cpe:/a:nullsoft:winamp:5.03
cpe:/a:nullsoft:winamp:2.10
...

© SecPod Technologies