CVE-2002-0284
 
Severity Score
2.6
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname.
Winamp 2.78 y 2.77, cuando abre un fichero wma (windows media audio) que necesita una licencia, envía la ruta completa del directorio de ficheros temporales de internet directamente a la página web que procesa la licencia, lo que podría permitir a servidores web maliciosos obtener la ruta.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2002-05-01 CVE Reserved
- 2002-05-03 CVE Published
- 2024-08-08 CVE Updated
- 2024-10-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=bugtraq&m=101408781031527&w=2 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nullsoft Search vendor "Nullsoft" | Winamp Search vendor "Nullsoft" for product "Winamp" | 2.77 Search vendor "Nullsoft" for product "Winamp" and version "2.77" | - |
Affected
| ||||||
Nullsoft Search vendor "Nullsoft" | Winamp Search vendor "Nullsoft" for product "Winamp" | 2.78 Search vendor "Nullsoft" for product "Winamp" and version "2.78" | - |
Affected
|