4.3

CVE-2008-3567

Cross-zone scripting vulnerability in the NowPlaying functionality in NullSoft Winamp before 5.541 allows remote attackers to conduct cross-site scripting (XSS) attacks via an MP3 file with JavaScript in id3 tags.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NullsoftWinamp Version <= 5.54
NullsoftWinamp Version2.0
NullsoftWinamp Version2.4
NullsoftWinamp Version2.5e
NullsoftWinamp Version2.6x
NullsoftWinamp Version2.7x
NullsoftWinamp Version2.10
NullsoftWinamp Version2.24
NullsoftWinamp Version2.50
NullsoftWinamp Version2.60
NullsoftWinamp Version2.61
NullsoftWinamp Version2.62
NullsoftWinamp Version2.64
NullsoftWinamp Version2.65
NullsoftWinamp Version2.70
NullsoftWinamp Version2.71
NullsoftWinamp Version2.72
NullsoftWinamp Version2.73
NullsoftWinamp Version2.74
NullsoftWinamp Version2.75
NullsoftWinamp Version2.76
NullsoftWinamp Version2.77
NullsoftWinamp Version2.78
NullsoftWinamp Version2.79
NullsoftWinamp Version2.80
NullsoftWinamp Version2.81
NullsoftWinamp Version2.90
NullsoftWinamp Version2.91
NullsoftWinamp Version2.95
NullsoftWinamp Version3.0
NullsoftWinamp Version3.1
NullsoftWinamp Version5.0
NullsoftWinamp Version5.0.1
NullsoftWinamp Version5.0.2
NullsoftWinamp Version5.01
NullsoftWinamp Version5.1
NullsoftWinamp Version5.02
NullsoftWinamp Version5.2
NullsoftWinamp Version5.3
NullsoftWinamp Version5.03
NullsoftWinamp Version5.03a
NullsoftWinamp Version5.04
NullsoftWinamp Version5.05
NullsoftWinamp Version5.5
NullsoftWinamp Version5.06
NullsoftWinamp Version5.07
NullsoftWinamp Version5.08
NullsoftWinamp Version5.08c
NullsoftWinamp Version5.08d
NullsoftWinamp Version5.08e
NullsoftWinamp Version5.09
NullsoftWinamp Version5.11
NullsoftWinamp Version5.12
NullsoftWinamp Version5.13
NullsoftWinamp Version5.21
NullsoftWinamp Version5.22
NullsoftWinamp Version5.23
NullsoftWinamp Version5.24
NullsoftWinamp Version5.31
NullsoftWinamp Version5.32
NullsoftWinamp Version5.33
NullsoftWinamp Version5.34
NullsoftWinamp Version5.35
NullsoftWinamp Version5.36
NullsoftWinamp Version5.51
NullsoftWinamp Version5.52
NullsoftWinamp Version5.53
NullsoftWinamp Version5.091
NullsoftWinamp Version5.093
NullsoftWinamp Version5.094
NullsoftWinamp Version5.111
NullsoftWinamp Version5.112
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.58% 0.662
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.