CVE-2002-0591
medium · 5Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag with a SRC attribute that specifies the target filename.
5
CVSS
11.6%
EPSS (exploit prob.)
96th
EPSS percentile
2002-06-18
Published
AV:N/AC:L/Au:N/C:N/I:P/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| aol | instant_messenger | 4.0 |
| aol | instant_messenger | 4.1 |
| aol | instant_messenger | 4.2 |
| aol | instant_messenger | 4.3 |
| aol | instant_messenger | 4.4 |
| aol | instant_messenger | 4.5 |
| aol | instant_messenger | 4.6 |
| aol | instant_messenger | 4.7 |
| aol | instant_messenger | 4.8_beta |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0203.html
- http://www.iss.net/security_center/static/8870.php
- http://www.securityfocus.com/bid/4526
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0203.html
- http://www.iss.net/security_center/static/8870.php
- http://www.securityfocus.com/bid/4526
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2002-0591