source: https://www.securityfocus.com/bid/11053/info A vulnerability in Winamp has been discovered that may permit remote attackers to execute arbitrary code on client computers through a malicious .WSZ Winamp skin file. This issue is currently being exploited in the wild. This vulnerability may be exploited through a Web site, or any other means that will allow the attacker to transmit the malicious file to a victim user. This vulnerability is reported to affect all versions of Winamp up to and including 5.04. index.html ----------- <body> </body> Load.php --------- foo.wsz (foo.zip) ----------------- /frame/ /maki/ /shade/ /html/ /html/file.exe (malicious file to execute) /html/test.htm (html to load the .exe) /player/ /player/Thumbs.db /xml/ /xml/includes.xml /xml/player-normal.xml /xml/player.xml /skin.xml /html/test.htm ---------------- /xml/includes.xml ------------------- /xml/player-normal.xml ------------------------- /xml/player.xml ----------------- /skin.xml --------- 1.0 Batman Petrol Designs info@petroldesigns.com http://www.petroldesigns.com