CVE-2004-0820 EXPLOIT
4.6
MEDIUM · CVSS 2.0 · EPSS 2.5% (pctl 84)
Patch early
A public exploit exists.
Description
Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are referenced from XML files contained in a .wsz skin file.
Scoring
| CVSS | 4.6 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.54% — more likely to be exploited than 84% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-08-28 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| nullsoft | winamp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Winamp 5.04 - '.wsz' Skin File Remote Code Execution | 2004-08-25 |
References
- http://secunia.com/advisories/12381/
- http://www.auscert.org.au/render.html?it=4338
- http://www.frsirt.com/exploits/08252004.skinhead.php
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17124
- http://secunia.com/advisories/12381/
- http://www.auscert.org.au/render.html?it=4338
- http://www.frsirt.com/exploits/08252004.skinhead.php
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17124
→ the Explorer · watch your stack · NVD