CVE-2008-3567
Winamp <5.541 - XSS
Title source: llmDescription
Cross-zone scripting vulnerability in the NowPlaying functionality in NullSoft Winamp before 5.541 allows remote attackers to conduct cross-site scripting (XSS) attacks via an MP3 file with JavaScript in id3 tags.
References (6)
Scores
EPSS
0.0058
EPSS Percentile
68.5%
Classification
CWE
CWE-79
Status
draft
Affected Products (50)
nullsoft/winamp
< 5.54
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
... and 35 more
Timeline
Published
Aug 10, 2008
Tracked Since
Feb 18, 2026