CVE-2008-3567

Cross-zone scripting vulnerability in the NowPlaying functionality in NullSoft Winamp before 5.541 allows remote attackers to conduct cross-site scripting (XSS) attacks via an MP3 file with JavaScript in id3 tags.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
VendorProductVersion
nullsoftwinamp
𝑥
≤ 5.54
nullsoftwinamp
2.0
nullsoftwinamp
2.4
nullsoftwinamp
2.5e:e
nullsoftwinamp
2.6x:x
nullsoftwinamp
2.7x:x
nullsoftwinamp
2.10
nullsoftwinamp
2.24
nullsoftwinamp
2.50
nullsoftwinamp
2.60
nullsoftwinamp
2.61
nullsoftwinamp
2.62
nullsoftwinamp
2.64
nullsoftwinamp
2.65
nullsoftwinamp
2.70
nullsoftwinamp
2.71
nullsoftwinamp
2.72
nullsoftwinamp
2.73
nullsoftwinamp
2.74
nullsoftwinamp
2.75
nullsoftwinamp
2.76
nullsoftwinamp
2.77
nullsoftwinamp
2.78
nullsoftwinamp
2.79
nullsoftwinamp
2.80
nullsoftwinamp
2.81
nullsoftwinamp
2.90
nullsoftwinamp
2.91
nullsoftwinamp
2.95
nullsoftwinamp
3.0
nullsoftwinamp
3.1
nullsoftwinamp
5.0
nullsoftwinamp
5.0.1
nullsoftwinamp
5.0.2
nullsoftwinamp
5.01
nullsoftwinamp
5.1
nullsoftwinamp
5.02
nullsoftwinamp
5.2
nullsoftwinamp
5.3
nullsoftwinamp
5.03
nullsoftwinamp
5.03a:a
nullsoftwinamp
5.04
nullsoftwinamp
5.05
nullsoftwinamp
5.5
nullsoftwinamp
5.06
nullsoftwinamp
5.07
nullsoftwinamp
5.08
nullsoftwinamp
5.08c:c
nullsoftwinamp
5.08d:d
nullsoftwinamp
5.08e:e
nullsoftwinamp
5.09
nullsoftwinamp
5.11
nullsoftwinamp
5.12
nullsoftwinamp
5.13
nullsoftwinamp
5.21
nullsoftwinamp
5.22
nullsoftwinamp
5.23
nullsoftwinamp
5.24
nullsoftwinamp
5.31
nullsoftwinamp
5.32
nullsoftwinamp
5.33
nullsoftwinamp
5.34
nullsoftwinamp
5.35
nullsoftwinamp
5.36
nullsoftwinamp
5.51
nullsoftwinamp
5.52
nullsoftwinamp
5.53
nullsoftwinamp
5.091
nullsoftwinamp
5.093
nullsoftwinamp
5.094
nullsoftwinamp
5.111
nullsoftwinamp
5.112
𝑥
= Vulnerable software versions