Lucene search

K
cveMitreCVE-2003-0228
HistoryMay 27, 2003 - 4:00 a.m.

CVE-2003-0228

2003-05-2704:00:00
mitre
web.nvd.nist.gov
32
cve
2003
0228
directory traversal vulnerability
microsoft
windows media player
remote attackers
arbitrary code
skins file
hex-encoded
backslash characters

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.95

Percentile

99.4%

Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.

Affected configurations

Nvd
Node
microsoftwindows_media_playerMatch-
OR
microsoftwindows_media_playerMatch7.1
VendorProductVersionCPE
microsoftwindows_media_player-cpe:2.3:a:microsoft:windows_media_player:-:*:*:*:*:*:*:*
microsoftwindows_media_player7.1cpe:2.3:a:microsoft:windows_media_player:7.1:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.95

Percentile

99.4%