CVE-2002-2392

Winamp 2.65 through 3.0 stores skin files in a predictable file location, which allows remote attackers to execute arbitrary code via a URL reference to (1) wsz and (2) wal files that contain embedded code.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nullsoft:winamp:2.65:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:2.70:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:2.71:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:2.72:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:2.73:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:2.74:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:2.75:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:2.76:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:2.77:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:2.78:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:2.79:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:2.80:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:3.1:*:*:*:*:*:*:*

History

20 Nov 2024, 23:43

Type Values Removed Values Added
References () http://seclists.org/bugtraq/2002/Jul/0205.html - () http://seclists.org/bugtraq/2002/Jul/0205.html -
References () http://www.iss.net/security_center/static/9630.php - () http://www.iss.net/security_center/static/9630.php -
References () http://www.securityfocus.com/bid/5266 - Exploit () http://www.securityfocus.com/bid/5266 - Exploit

Information

Published : 2002-12-31 05:00

Updated : 2024-11-20 23:43


NVD link : CVE-2002-2392

Mitre link : CVE-2002-2392

CVE.ORG link : CVE-2002-2392


JSON object : View

Products Affected

nullsoft

  • winamp