peter bassill · operator
$ cve CVE-2004-0820 JSON

CVE-2004-0820 EXPLOIT

4.6
MEDIUM · CVSS 2.0 · EPSS 2.5% (pctl 84)

Patch early

A public exploit exists.

Description

Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are referenced from XML files contained in a .wsz skin file.

Scoring

CVSS4.6 (MEDIUM, v2.0)
VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS2.54% — more likely to be exploited than 84% of all CVEs
On CISA KEVno
Public exploityes
Published2004-08-28
Last modified2026-06-16

Affected (1)

VendorProduct
nullsoftwinamp

Public exploits

SourceTitleDate
exploit-dbWinamp 5.04 - '.wsz' Skin File Remote Code Execution2004-08-25

References

→ the Explorer  ·  watch your stack  ·  NVD