Lucene search

K
cveMitreCVE-2008-3567
HistoryAug 10, 2008 - 8:41 p.m.

CVE-2008-3567

2008-08-1020:41:00
CWE-79
mitre
web.nvd.nist.gov
23
4
cve
2008
3567
nullsoft winamp
cross-zone scripting
vulnerability
xss
mp3
id3 tags

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.003

Percentile

71.7%

Cross-zone scripting vulnerability in the NowPlaying functionality in NullSoft Winamp before 5.541 allows remote attackers to conduct cross-site scripting (XSS) attacks via an MP3 file with JavaScript in id3 tags.

Affected configurations

Nvd
Node
nullsoftwinampRange5.54
OR
nullsoftwinampMatch2.0
OR
nullsoftwinampMatch2.4
OR
nullsoftwinampMatch2.5e
OR
nullsoftwinampMatch2.6x
OR
nullsoftwinampMatch2.7x
OR
nullsoftwinampMatch2.10
OR
nullsoftwinampMatch2.24
OR
nullsoftwinampMatch2.50
OR
nullsoftwinampMatch2.60
OR
nullsoftwinampMatch2.61
OR
nullsoftwinampMatch2.62
OR
nullsoftwinampMatch2.64
OR
nullsoftwinampMatch2.65
OR
nullsoftwinampMatch2.70
OR
nullsoftwinampMatch2.71
OR
nullsoftwinampMatch2.72
OR
nullsoftwinampMatch2.73
OR
nullsoftwinampMatch2.74
OR
nullsoftwinampMatch2.75
OR
nullsoftwinampMatch2.76
OR
nullsoftwinampMatch2.77
OR
nullsoftwinampMatch2.78
OR
nullsoftwinampMatch2.79
OR
nullsoftwinampMatch2.80
OR
nullsoftwinampMatch2.81
OR
nullsoftwinampMatch2.90
OR
nullsoftwinampMatch2.91
OR
nullsoftwinampMatch2.95
OR
nullsoftwinampMatch3.0
OR
nullsoftwinampMatch3.1
OR
nullsoftwinampMatch5.0
OR
nullsoftwinampMatch5.0.1
OR
nullsoftwinampMatch5.0.2
OR
nullsoftwinampMatch5.01
OR
nullsoftwinampMatch5.1
OR
nullsoftwinampMatch5.02
OR
nullsoftwinampMatch5.2
OR
nullsoftwinampMatch5.3
OR
nullsoftwinampMatch5.03
OR
nullsoftwinampMatch5.03a
OR
nullsoftwinampMatch5.04
OR
nullsoftwinampMatch5.05
OR
nullsoftwinampMatch5.5
OR
nullsoftwinampMatch5.06
OR
nullsoftwinampMatch5.07
OR
nullsoftwinampMatch5.08
OR
nullsoftwinampMatch5.08c
OR
nullsoftwinampMatch5.08d
OR
nullsoftwinampMatch5.08e
OR
nullsoftwinampMatch5.09
OR
nullsoftwinampMatch5.11
OR
nullsoftwinampMatch5.12
OR
nullsoftwinampMatch5.13
OR
nullsoftwinampMatch5.21
OR
nullsoftwinampMatch5.22
OR
nullsoftwinampMatch5.23
OR
nullsoftwinampMatch5.24
OR
nullsoftwinampMatch5.31
OR
nullsoftwinampMatch5.32
OR
nullsoftwinampMatch5.33
OR
nullsoftwinampMatch5.34
OR
nullsoftwinampMatch5.35
OR
nullsoftwinampMatch5.36
OR
nullsoftwinampMatch5.51
OR
nullsoftwinampMatch5.52
OR
nullsoftwinampMatch5.53
OR
nullsoftwinampMatch5.091
OR
nullsoftwinampMatch5.093
OR
nullsoftwinampMatch5.094
OR
nullsoftwinampMatch5.111
OR
nullsoftwinampMatch5.112
VendorProductVersionCPE
nullsoftwinamp*cpe:2.3:a:nullsoft:winamp:*:*:*:*:*:*:*:*
nullsoftwinamp2.0cpe:2.3:a:nullsoft:winamp:2.0:*:*:*:*:*:*:*
nullsoftwinamp2.4cpe:2.3:a:nullsoft:winamp:2.4:*:*:*:*:*:*:*
nullsoftwinamp2.5ecpe:2.3:a:nullsoft:winamp:2.5e:*:*:*:*:*:*:*
nullsoftwinamp2.6xcpe:2.3:a:nullsoft:winamp:2.6x:*:*:*:*:*:*:*
nullsoftwinamp2.7xcpe:2.3:a:nullsoft:winamp:2.7x:*:*:*:*:*:*:*
nullsoftwinamp2.10cpe:2.3:a:nullsoft:winamp:2.10:*:*:*:*:*:*:*
nullsoftwinamp2.24cpe:2.3:a:nullsoft:winamp:2.24:*:*:*:*:*:*:*
nullsoftwinamp2.50cpe:2.3:a:nullsoft:winamp:2.50:*:*:*:*:*:*:*
nullsoftwinamp2.60cpe:2.3:a:nullsoft:winamp:2.60:*:*:*:*:*:*:*
Rows per page:
1-10 of 721

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.003

Percentile

71.7%

Related for CVE-2008-3567