Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2002-1015


RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by Internet Explorer or other Microsoft-based web readers.


Published

2002-10-04T04:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application realnetworks realjukebox_2 1.0.2.340 Yes
Application realnetworks realjukebox_2 1.0.2.379 Yes
Application realnetworks realjukebox_2_plus 1.0.2.340 Yes
Application realnetworks realjukebox_2_plus 1.0.2.379 Yes
Application realnetworks realone_player 6.0.10.505 Yes

References