CVE-2002-2169

AOL Instant Messenger - XSS

Title source: rule
STIX 2.1

Description

Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activities, such as adding buddies and groups to a user's buddy list, via a URL with a META HTTP-EQUIV="refresh" tag to an aim: URL.

Exploits (1)

exploitdb WORKING POC VERIFIED
by orb · textremotewindows
https://www.exploit-db.com/exploits/21619

References (4)

Core 4
Core References
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9616.php
Exploit x_refsource_misc
http://www.mindflip.org/aim.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/282443
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5246

Scores

EPSS 0.0443
EPSS Percentile 89.1%

Details

Status published
Products (3)
aol/instant_messenger 4.5
aol/instant_messenger 4.7
aol/instant_messenger 4.7.2480
Published Dec 31, 2002
Tracked Since Feb 18, 2026