CVE-2002-1813

AOL Instant Messenger 4.8.2790 - Remote Code Execution via Link Href Attribute

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1813. PoCs published by Blud Clot.

AI-analyzed exploit summary This exploit leverages a path traversal vulnerability in AOL Instant Messenger (AIM) to execute arbitrary local files when a user clicks a malicious link. The attack relies on the client's filesystem structure and requires no spaces in the file path.

Description

Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8.2790 allows remote attackers to execute arbitrary programs by specifying the program in the href attribute of a link.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Blud Clot · textremotewindows
https://www.exploit-db.com/exploits/21958

This exploit leverages a path traversal vulnerability in AOL Instant Messenger (AIM) to execute arbitrary local files when a user clicks a malicious link. The attack relies on the client's filesystem structure and requires no spaces in the file path.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: AOL Instant Messenger 4.8.2790
No auth needed
Prerequisites: Knowledge of the target's local filesystem structure · Presence of an executable file with no spaces in its path
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-10/0319.html
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6027

Scores

EPSS 0.0687
EPSS Percentile 93.4%

Details

Status published
Products (4)
aol/instant_messenger 4.7.2480
aol/instant_messenger 4.8.2616
aol/instant_messenger 4.8.2646
aol/instant_messenger 5.0.2938
Published Dec 31, 2002
Tracked Since Feb 18, 2026