CVE-2002-1015
Summary
| CVE | CVE-2002-1015 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-10-04 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by Internet Explorer or other Microsoft-based web readers. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Realnetworks | Realjukebox 2 | 1.0.2.340 | All | All | All |
| Application | Realnetworks | Realjukebox 2 | 1.0.2.379 | All | All | All |
| Application | Realnetworks | Realjukebox 2 Plus | 1.0.2.340 | All | All | All |
| Application | Realnetworks | Realjukebox 2 Plus | 1.0.2.379 | All | All | All |
| Application | Realnetworks | Realone Player | 6.0.10.505 | gold | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ISS X-Force Database: realplayer-rjs-file-download (9539): RealOne Player Gold and RealJukebox2 RJS skin file download and execution | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Patch, Vendor Advisory |
| CERT/CC Vulnerability Note VU#888547 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Neohapsis Archives - Bugtraq - [SPSadvisory#47]RealONE Player Gold / RealJukebox2 skin file download vulnerability - From webmaster_at_shadowpenguin.org | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| RealNetworks Support: Buffer Overrun Exploit | af854a3a-2127-422b-91ae-364da2661108 | service.real.com | |
| Real Networks RealJukebox Predictable File Extraction Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.