CVE-2003-0726 EXPLOIT
5.1
MEDIUM · CVSS 2.0 · EPSS 6.8% (pctl 94)
Patch early
A public exploit exists.
Description
RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scripting protocol, which is executed in the security context of the previously loaded URL, as demonstrated using a "javascript:" URL in the area tag.
Scoring
| CVSS | 5.1 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
| EPSS | 6.83% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-10-20 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| realnetworks | realone desktop manager |
| realnetworks | realone enterprise desktop |
| realnetworks | realone player |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | RealOne Player 1.0/2.0/6.0.10/6.0.11 - '.SMIL' File Script Execution | 2003-08-19 |
References
- http://securitytracker.com/id?1007532
- http://www.digitalpranksters.com/advisories/realnetworks/smilscriptprotocol.html
- http://www.securityfocus.com/archive/1/335293
- http://www.securityfocus.com/bid/8453
- http://www.service.real.com/help/faq/security/securityupdate_august2003.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13028
- http://securitytracker.com/id?1007532
- http://www.digitalpranksters.com/advisories/realnetworks/smilscriptprotocol.html
- http://www.securityfocus.com/archive/1/335293
- http://www.securityfocus.com/bid/8453
- http://www.service.real.com/help/faq/security/securityupdate_august2003.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13028
→ the Explorer · watch your stack · NVD