CVE-2002-0284

Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nullsoft:winamp:2.77:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:2.78:*:*:*:*:*:*:*

History

20 Nov 2024, 23:38

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=101408781031527&w=2 - () http://marc.info/?l=bugtraq&m=101408781031527&w=2 -

Information

Published : 2002-05-31 04:00

Updated : 2024-11-20 23:38


NVD link : CVE-2002-0284

Mitre link : CVE-2002-0284

CVE.ORG link : CVE-2002-0284


JSON object : View

Products Affected

nullsoft

  • winamp