5
CVSSv2

CVE-2002-0591

Published: 18/06/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and previous versions allows remote malicious users to create arbitrary files and execute commands via a Direct Connection with an IMG tag with a SRC attribute that specifies the target filename.

Vulnerable Product Search on Vulmon Subscribe to Product

aol instant messenger 4.2

aol instant messenger 4.0

aol instant messenger 4.5

aol instant messenger 4.3

aol instant messenger 4.8 beta

aol instant messenger 4.6

aol instant messenger 4.7

aol instant messenger 4.4

aol instant messenger 4.1

Exploits

source: wwwsecurityfocuscom/bid/4526/info An issue has been reported, which could allow an AIM user to save files to arbitrary locations Reportedly, this is achievable when a direct connection is made between two AIM users Files that are sent to a user include an img tag and a data tag Upon a file being sent, the recipient's client wi ...