CVE-2003-0228

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/05/2003
Last modified:
03/04/2025

Description

Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:windows_media_player:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:windows_media_player:7.1:*:*:*:*:*:*:*