Unrated severityNVD Advisory· Published Nov 23, 2004· Updated Apr 16, 2026
CVE-2004-0273
CVE-2004-0273
Description
Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file.
Affected products
10- cpe:2.3:a:realnetworks:realone_desktop_manager:*:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realone_enterprise_desktop:6.0.11.774:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realone_player:1.0:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:realnetworks:realone_player:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realone_player:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realone_player:2.0:*:win:*:*:*:*:*
- cpe:2.3:a:realnetworks:realone_player:6.0.11.818:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realone_player:6.0.11.830:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realone_player:6.0.11.841:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realone_player:6.0.11.853:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realone_player:6.0.11.868:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- service.real.com/help/faq/security/040123_player/EN/nvdPatchVendor Advisory
- www.securityfocus.com/bid/9580nvdPatchVendor Advisory
- www.kb.cert.org/vuls/id/514734nvdUS Government Resource
- marc.infonvd
- exchange.xforce.ibmcloud.com/vulnerabilities/15123nvd
News mentions
0No linked articles in our index yet.