CVE-2004-0820

critical

Description

Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are referenced from XML files contained in a .wsz skin file.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/17124

http://www.frsirt.com/exploits/08252004.skinhead.php

http://www.auscert.org.au/render.html?it=4338

http://secunia.com/advisories/12381/

Details

Source: Mitre, NVD

Published: 2004-08-28

Updated: 2017-07-11

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical