PT-2006-7117 · Nullsoft · Winamp Web Interface
Luigi Auriemma
·
Published
2006-12-14
·
Updated
2018-10-17
·
CVE-2006-6513
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Winamp Web Interface (Wawi) versions 7.5.13 and earlier
Description
The issue allows remote authenticated users to download arbitrary file types under the root via a trailing "." (dot) in a filename in the
file parameter. This is related to erroneous behavior of the IsWinampFile function when handling the /dl URI in the CControl::Download function.Recommendations
For Winamp Web Interface (Wawi) versions 7.5.13 and earlier, consider restricting access to the
/dl URI until a fix is available. As a temporary workaround, avoid using the file parameter with a trailing "." (dot) in filenames to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Winamp Web Interface