Back
CVE-2002-0546
Cross-site scripting vulnerability in the mini-browser for Winamp 2.78 and 2.79 allows remote attackers to execute script via an ID3v1 or ID3v2 tag in an MP3 file.
Published: Jul 3, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| nullsoft | winamp | 2.78 |
| nullsoft | winamp | 2.79 |
GitHub Security Advisory GHSA-h32h-w8cj-pmf9
Cross-site scripting vulnerability in the mini-browser for Winamp 2.78 and 2.79 allows remote...
References (8)
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0026.html
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0049.html Exploit, Vendor Advisory
- http://www.iss.net/security_center/static/8753.php Vendor Advisory
- http://www.securityfocus.com/bid/4414
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0026.html
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0049.html Exploit, Vendor Advisory
- http://www.iss.net/security_center/static/8753.php Vendor Advisory
- http://www.securityfocus.com/bid/4414
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.73%
Top 25% most likely to be exploited
Threat Score
30.5 / 100
Data Sources
NVD
EPSS
GitHub