CVE-2008-3567

Winamp <5.541 - XSS

Title source: llm

Description

Cross-zone scripting vulnerability in the NowPlaying functionality in NullSoft Winamp before 5.541 allows remote attackers to conduct cross-site scripting (XSS) attacks via an MP3 file with JavaScript in id3 tags.

Scores

EPSS 0.0058
EPSS Percentile 68.5%

Classification

CWE
CWE-79
Status draft

Affected Products (50)

nullsoft/winamp < 5.54
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
nullsoft/winamp
... and 35 more

Timeline

Published Aug 10, 2008
Tracked Since Feb 18, 2026