Vulnerability Name: | CVE-2003-0228 (CCN-11953) | ||||||||
Assigned: | 2003-05-07 | ||||||||
Published: | 2003-05-07 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2003-0228 Source: BUGTRAQ Type: UNKNOWN 20030507 Windows Media Player directory traversal vulnerability Source: BUGTRAQ Type: UNKNOWN 20030508 why i love xs4all + mediaplayer thingie Source: NTBUGTRAQ Type: UNKNOWN 20030507 Windows Media Player directory traversal vulnerability Source: CCN Type: CIAC Information Bulletin N-092 Microsoft Windows Media Player Skins Flaw Source: CCN Type: US-CERT VU#384932 Microsoft Windows Media Player fails to properly evaluate URLs when downloading skin files Source: CERT-VN Type: US Government Resource VU#384932 Source: CCN Type: Microsoft Security Bulletin MS03-017 Flaw in Windows Media Player Skins Downloading could allow Code Execution (817787) Source: CCN Type: OSVDB ID: 7738 Microsoft Windows Media Player Skins File Arbitrary Command Execution Source: BID Type: Exploit, Patch, Vendor Advisory 7517 Source: CCN Type: BID-7517 Microsoft Windows Media Player Skin File Code Execution Vulnerability Source: MS Type: UNKNOWN MS03-017 Source: XF Type: UNKNOWN mediaplayer-skin-code-execution(11953) Source: XF Type: UNKNOWN mediaplayer-skin-code-execution(11953) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:321 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |