First published: Sun Aug 10 2008(Updated: )
Cross-zone scripting vulnerability in the NowPlaying functionality in NullSoft Winamp before 5.541 allows remote attackers to conduct cross-site scripting (XSS) attacks via an MP3 file with JavaScript in id3 tags.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Winamp iPod Plugin | =2.6x | |
Winamp iPod Plugin | =5.093 | |
Winamp iPod Plugin | =2.64 | |
Winamp iPod Plugin | =5.36 | |
Winamp iPod Plugin | =5.24 | |
Winamp iPod Plugin | =2.62 | |
Winamp iPod Plugin | =5.111 | |
Winamp iPod Plugin | =2.24 | |
Winamp iPod Plugin | =5.09 | |
Winamp iPod Plugin | <=5.54 | |
Winamp iPod Plugin | =2.50 | |
Winamp iPod Plugin | =5.31 | |
Winamp iPod Plugin | =5.05 | |
Winamp iPod Plugin | =2.72 | |
Winamp iPod Plugin | =5.23 | |
Winamp iPod Plugin | =2.73 | |
Winamp iPod Plugin | =2.90 | |
Winamp iPod Plugin | =2.61 | |
Winamp iPod Plugin | =5.112 | |
Winamp iPod Plugin | =2.75 | |
Winamp iPod Plugin | =5.02 | |
Winamp iPod Plugin | =5.01 | |
Winamp iPod Plugin | =5.53 | |
Winamp iPod Plugin | =5.33 | |
Winamp iPod Plugin | =2.65 | |
Winamp iPod Plugin | =5.5 | |
Winamp iPod Plugin | =5.34 | |
Winamp iPod Plugin | =5.0.2 | |
Winamp iPod Plugin | =3.1 | |
Winamp iPod Plugin | =5.12 | |
Winamp iPod Plugin | =2.76 | |
Winamp iPod Plugin | =2.80 | |
Winamp iPod Plugin | =2.91 | |
Winamp iPod Plugin | =5.21 | |
Winamp iPod Plugin | =5.094 | |
Winamp iPod Plugin | =5.1 | |
Winamp iPod Plugin | =2.74 | |
Winamp iPod Plugin | =5.3 | |
Winamp iPod Plugin | =2.71 | |
Winamp iPod Plugin | =5.04 | |
Winamp iPod Plugin | =5.03a | |
Winamp iPod Plugin | =5.32 | |
Winamp iPod Plugin | =2.78 | |
Winamp iPod Plugin | =2.81 | |
Winamp iPod Plugin | =5.08d | |
Winamp iPod Plugin | =5.08 | |
Winamp iPod Plugin | =5.0.1 | |
Winamp iPod Plugin | =2.77 | |
Winamp iPod Plugin | =5.11 | |
Winamp iPod Plugin | =2.5e | |
Winamp iPod Plugin | =2.4 | |
Winamp iPod Plugin | =5.51 | |
Winamp iPod Plugin | =5.06 | |
Winamp iPod Plugin | =2.0 | |
Winamp iPod Plugin | =5.07 | |
Winamp iPod Plugin | =5.13 | |
Winamp iPod Plugin | =2.10 | |
Winamp iPod Plugin | =2.60 | |
Winamp iPod Plugin | =5.091 | |
Winamp iPod Plugin | =5.52 | |
Winamp iPod Plugin | =5.2 | |
Winamp iPod Plugin | =3.0 | |
Winamp iPod Plugin | =2.70 | |
Winamp iPod Plugin | =2.95 | |
Winamp iPod Plugin | =5.03 | |
Winamp iPod Plugin | =2.7x | |
Winamp iPod Plugin | =2.79 | |
Winamp iPod Plugin | =5.0 | |
Winamp iPod Plugin | =5.08e | |
Winamp iPod Plugin | =5.35 | |
Winamp iPod Plugin | =5.22 | |
Winamp iPod Plugin | =5.08c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3567 has a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2008-3567, upgrade to a version of Winamp that is greater than or equal to 5.541.
CVE-2008-3567 affects NullSoft Winamp versions 2.6x through 5.541.
CVE-2008-3567 is a cross-zone scripting vulnerability that allows for XSS attacks.
Yes, CVE-2008-3567 can be exploited remotely through specially crafted MP3 files containing malicious JavaScript in ID3 tags.