CVE-2002-1015
Last modified
CVE-2002-1015 is a vulnerability of currently unknown severity. RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by Internet Explorer or other Microsoft-based web readers.. EPSS estimates a 2.04% chance of exploitation in the next 30 days.
Description
RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by Internet Explorer or other Microsoft-based web readers.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Realnetworks | Realjukebox 2 | 1.0.2.340 | — |
| Realnetworks | Realjukebox 2 | 1.0.2.379 | — |
| Realnetworks | Realjukebox 2 Plus | 1.0.2.340 | — |
| Realnetworks | Realjukebox 2 Plus | 1.0.2.379 | — |
| Realnetworks | Realone Player | 6.0.10.505 | Gold |
References
- http://www.iss.net/security_center/static/9539.phpPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/888547US Government Resource
- http://www.securityfocus.com/bid/5210Patch, Vendor Advisory
- http://www.iss.net/security_center/static/9539.phpPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/888547US Government Resource
- http://www.securityfocus.com/bid/5210Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-1015?
How severe is CVE-2002-1015?
How do I fix CVE-2002-1015?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2002
- CVE-2002-1009Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, …
- CVE-2002-1010Lotus Domino R4 allows remote attackers to bypass access res…
- CVE-2002-1011Buffer overflow in web server for Tivoli Management Framewor…
- CVE-2002-1012Buffer overflow in web server for Tivoli Management Framewor…
- CVE-2002-1013Buffer overflow in traffic_manager for Inktomi Traffic Serve…
- CVE-2002-1014Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, an…
- CVE-2002-1016Adobe eBook Reader allows a user to bypass restrictions for …
- CVE-2002-1017Adobe eBook Reader 2.1 and 2.2 allows a user to copy eBooks …
- CVE-2002-1018The library feature for Adobe Content Server 3.0 does not ve…
- CVE-2002-1019The library feature for Adobe Content Server 3.0 allows a re…
- CVE-2002-1020The library feature for Adobe Content Server 3.0 allows a re…
- CVE-2002-1021BadBlue server allows remote attackers to read restricted fi…
Are you affected by CVE-2002-1015?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
