20020416 AIM's 'Direct Connection' feature could lead to arbitrary file creationmailing list
http://archives.neohapsis.com/archives/bugtraq/2002-04/0203.html CVE-2002-0591
AOL Instant Messenger 4.x - Arbitrary File Creation
Record summary
CVE-2002-0591 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag with a SRC attribute that specifies the target filename.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAOL Instant Messenger 4.x - Arbitrary File CreationExploitDB exploitby Noah JohnsonNot analyzed1 file
References
4aim-direct-connection-files(8870)vdb entry
http://www.iss.net/security_center/static/8870.php 4526vdb entry
http://www.securityfocus.com/bid/4526 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0591