Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag with a SRC attribute that specifies the target filename.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/8870.php | patch vendor advisory vdb entry |
http://www.securityfocus.com/bid/4526 | vendor advisory vdb entry exploit |
http://archives.neohapsis.com/archives/bugtraq/2002-04/0203.html | patch vendor advisory mailing list exploit |