{"api_version":"1","generated_at":"2026-07-23T08:54:46+00:00","cve":"CVE-2020-7803","urls":{"html":"https://cve.report/CVE-2020-7803","api":"https://cve.report/api/cve/CVE-2020-7803.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-7803","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-7803"},"summary":{"title":"CVE-2020-7803","description":"IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donwload vulnerability in ZInsX.ocx of IMGTech Co,Ltd Zoneplayer allows attacker to cause arbitrary code execution.","state":"PUBLIC","assigner":"vuln@krcert.or.kr","published_at":"2020-05-07 18:15:00","updated_at":"2020-08-06 13:34:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"http://www.zoneplayer.co.kr/","name":"http://www.zoneplayer.co.kr/","refsource":"CONFIRM","tags":["Product","Vendor Advisory"],"title":"존플레이어 미디어보안 동영상보안 모바일플레이어 HTML5플레이어","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35346","name":"https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35346","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"KrCERT/CC - KISA 인터넷 보호나라&KrCERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-7803","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7803","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Yu, Donghyun","lang":""}],"nvd_cpes":[{"cve_year":"2020","cve_id":"7803","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"imgtech","cpe5":"zoneplayer","cpe6":"2.0.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7803","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"imgtech","cpe5":"zoneplayer","cpe6":"2.0.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7803","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"imgtech","cpe5":"zoneplayer","cpe6":"2.0.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7803","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"imgtech","cpe5":"zoneplayer","cpe6":"2.0.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7803","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7803","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"vuln@krcert.or.kr","ID":"CVE-2020-7803","STATE":"PUBLIC","TITLE":"Zoneplayer ActiveX File Download Vulnerability"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"IMGTech Co,Ltd","product":{"product_data":[{"product_name":"Zoneplayer","version":{"version_data":[{"version_value":"2.0.1.4 and prior"}]}}]}}]}},"credit":[{"lang":"eng","value":"Yu, Donghyun"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donwload vulnerability in ZInsX.ocx of IMGTech Co,Ltd Zoneplayer allows attacker to cause arbitrary code execution."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20 Improper Input Validation"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35346","url":"https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35346"},{"refsource":"CONFIRM","name":"http://www.zoneplayer.co.kr/","url":"http://www.zoneplayer.co.kr/"}]},"source":{"discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2020-05-07 18:15:00","lastModifiedDate":"2020-08-06 13:34:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:imgtech:zoneplayer:2.0.1.3:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:imgtech:zoneplayer:2.0.1.4:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"7803","Ordinal":"168086","Title":"CVE-2020-7803","CVE":"CVE-2020-7803","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"7803","Ordinal":"1","NoteData":"IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donwload vulnerability in ZInsX.ocx of IMGTech Co,Ltd Zoneplayer allows attacker to cause arbitrary code execution.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"7803","Ordinal":"2","NoteData":"2020-05-07","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"7803","Ordinal":"3","NoteData":"2020-05-07","Type":"Other","Title":"Modified"}]}}}