PT-2001-2510 · Aol · Aol Instant Messenger

Publicado

2001-01-18

·

Atualizado

2008-09-05

·

CVE-2001-1416

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AOL Instant Messenger (AIM) version 4.4
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities in log messages within certain Alpha versions of the software. These vulnerabilities allow remote attackers to execute arbitrary web script or HTML via images in the DATA, STYLE, or BINARY tags.
Recommendations For AOL Instant Messenger (AIM) version 4.4, update to a version that addresses these XSS vulnerabilities to prevent remote attackers from executing arbitrary web scripts.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-1416

Produtos afetados

Aol Instant Messenger