The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers to use a shell: URI to exploit other vulnerabilities that involve predictable locations.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/354448 | mailing list vendor advisory |
http://www.securityfocus.com/bid/9698 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15310 | vdb entry |