NVD Vulnerability Detail
Search Exploit, PoC
CVE-2006-0787
Summary

wimpy_trackplays.php in Plaino Wimpy MP3 Player, possibly 5.2 and earlier, allows remote attackers to insert arbitrary strings into trackme.txt via the (1) trackFile, (2) trackArtist, and (3) trackTitle parameters, which can result in providing false information about songs, occupying excessive disk space with very long parameter values, and storing executable code that might be invoked through a different vulnerability. NOTE: since this issue, as described by the original researcher, is entirely dependent on the presence of another vulnerability, it could be argued that Wimpy cannot be responsible for how its data file is processed by applications outside of its control. Since this issue might only be useful as a facilitator manipulation in another vulnerability, perhaps it should not be included in CVE.

Publication Date Feb. 19, 2006, 8:02 p.m.
Registration Date Jan. 29, 2021, 3:31 p.m.
Last Update July 20, 2017, 10:30 a.m.
CVSS2.0 : MEDIUM
Score 4.0
Vector AV:N/AC:H/Au:N/C:N/I:P/A:P
攻撃元区分(AV) ネットワーク
攻撃条件の複雑さ(AC)
攻撃前の認証要否(Au) 不要
機密性への影響(C) なし
完全性への影響(I)
可用性への影響(A)
Get all privileges. いいえ
Get user privileges いいえ
Get other privileges いいえ
User operation required いいえ
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:plaino:wimpy_mp3:*:*:*:*:*:*:*:* 5.2
Related information, measures and tools
Common Vulnerabilities List