CVE-2004-0820
EXPLOITEDWinamp < 5.0.4 - Remote Code Execution via Malicious Skin File
Title source: llmExploitation Summary
CVE-2004-0820 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Petrol Designs.
AI-analyzed exploit summary This exploit leverages a vulnerability in Winamp (CVE-2004-0820) by tricking the user into loading a malicious skin file (foo.wsz) that executes an arbitrary executable (file.exe) via an embedded HTML object. The attack chain involves a phishing-like redirect (load.php) to deliver the malicious skin.
Description
Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are referenced from XML files contained in a .wsz skin file.
Exploits (1)
This exploit leverages a vulnerability in Winamp (CVE-2004-0820) by tricking the user into loading a malicious skin file (foo.wsz) that executes an arbitrary executable (file.exe) via an embedded HTML object. The attack chain involves a phishing-like redirect (load.php) to deliver the malicious skin.