CVE Vulnerabilities

CVE-2003-0228

Published: May 27, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.

Affected Software

NameVendorStart VersionEnd Version
Windows_media_playerMicrosoft- (including)- (including)
Windows_media_playerMicrosoft7.1 (including)7.1 (including)

References