CVE-2002-0591
AOL Instant Messenger - Directory Traversal and Arbitrary File Write via IMG Tag SRC Attribute
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-0591. PoCs published by Noah Johnson.
AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in AOL Instant Messenger (AIM) to save files to arbitrary locations on a recipient's system by manipulating the SRC parameter of an img tag. The attack requires a direct connection between two AIM users and involves injecting malicious file data into the communication stream.
Description
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag with a SRC attribute that specifies the target filename.
Exploits (1)
This exploit leverages a directory traversal vulnerability in AOL Instant Messenger (AIM) to save files to arbitrary locations on a recipient's system by manipulating the SRC parameter of an img tag. The attack requires a direct connection between two AIM users and involves injecting malicious file data into the communication stream.