MEDIUM
wimpy_trackplays.php in Plaino Wimpy MP3 Player, possibly 5.2 and earlier, allows remote attackers to insert arbitrary strings into trackme.txt via the (1) trackFile, (2) trackArtist, and (3) trackTitle parameters, which can result in providing false information about songs, occupying excessive disk space with very long parameter values, and storing executable code that might be invoked through a different vulnerability
Published Feb 19, 2006
4.0
MEDIUMCVSS 2.0
EPSS 2.22%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.