5
CVSSv2

CVE-2002-2169

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote malicious users to conduct unauthorized activities, such as adding buddies and groups to a user's buddy list, via a URL with a META HTTP-EQUIV="refresh" tag to an aim: URL.

Vulnerable Product Search on Vulmon Subscribe to Product

aol instant messenger 4.7

aol instant messenger 4.5

aol instant messenger 4.7.2480

Exploits

source: wwwsecurityfocuscom/bid/5246/info The AOL Instant Messenger client is prone to an issue which may allow maliciously crafted HTML to perform unauthorized actions (such as adding entries to the buddy list) on behalf of the user of a vulnerable client This condition is due to how the client handles "aim:" URIs These actions will b ...