Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
nullsoft winamp 2.77 |
||
nullsoft winamp 2.78 |