First published: Sat Aug 28 2004(Updated: )
Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are referenced from XML files contained in a .wsz skin file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Winamp iPod Plugin | =2.64 | |
Winamp iPod Plugin | =2.24 | |
Winamp iPod Plugin | =2.70 | |
Winamp iPod Plugin | =2.50 | |
Winamp iPod Plugin | =2.72 | |
Winamp iPod Plugin | =2.73 | |
Winamp iPod Plugin | =2.60 | |
Winamp iPod Plugin | =2.75 | |
Winamp iPod Plugin | =5.02 | |
Winamp iPod Plugin | =5.01 | |
Winamp iPod Plugin | =2.62 | |
Winamp iPod Plugin | =2.65 | |
Winamp iPod Plugin | =3.1 | |
Winamp iPod Plugin | =2.76 | |
Winamp iPod Plugin | =2.80 | |
Winamp iPod Plugin | =2.91 | |
Winamp iPod Plugin | =2.74 | |
Winamp iPod Plugin | =2.71 | |
Winamp iPod Plugin | =5.04 | |
Winamp iPod Plugin | =2.78 | |
Winamp iPod Plugin | =2.81 | |
Winamp iPod Plugin | =2.77 | |
Winamp iPod Plugin | =2.5e | |
Winamp iPod Plugin | =2.4 | |
Winamp iPod Plugin | =2.61 | |
Winamp iPod Plugin | =2.10 | |
Winamp iPod Plugin | =3.0 | |
Winamp iPod Plugin | =2.70 | |
Winamp iPod Plugin | =5.03 | |
Winamp iPod Plugin | =2.79 | |
Winamp iPod Plugin | =2.60 | |
Winamp iPod Plugin | =2.64 | |
Winamp iPod Plugin | =2.73 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0820 is classified as a medium severity vulnerability due to its potential for executing arbitrary scripts remotely.
To fix CVE-2004-0820, upgrade to Winamp version 5.0.4 or later which includes the necessary security patches.
CVE-2004-0820 affects multiple versions of Winamp including versions 2.24 through 2.91 and 5.01 through 5.03.
CVE-2004-0820 is a remote code execution vulnerability that allows attackers to execute arbitrary scripts from specially crafted skin files.
Yes, CVE-2004-0820 can be exploited without user interaction if a user opens a malicious skin file.