Cross-zone scripting vulnerability in the NowPlaying functionality in NullSoft Winamp before 5.541 allows remote attackers to conduct cross-site scripting (XSS) attacks via an MP3 file with JavaScript in id3 tags.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15716 | signature vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44207 | vdb entry |
http://forums.winamp.com/showthread.php?threadid=295505 | patch |
http://secunia.com/advisories/31371 | patch vendor advisory third party advisory |
http://blog.watchfire.com/wfblog/2008/09/winamp-nowplayi.html | |
http://www.securityfocus.com/bid/30539 | patch vdb entry |