← Back

CVE-2002-2392

nvd nist
Published: Dec 31, 2002Modified: Apr 16, 2026

JSON object

Loading...
6.4
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:N
Exploitability: 10.0 / Impact: 4.9
Source: NVD

Description

Winamp 2.65 through 3.0 stores skin files in a predictable file location, which allows remote attackers to execute arbitrary code via a URL reference to (1) wsz and (2) wal files that contain embedded code.

Affected (13)

Products: Nullsoft: Winamp
1 product
Winamp
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Nullsoft
Version 2.65
Version 2.70
Version 2.71
Version 2.72
Version 2.73
Version 2.74
Version 2.75
Version 2.76
Version 2.77
Version 2.78
Version 2.79
Version 2.80
Version 3.1

References (6)

Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.