PT-2001-2510 · Aol · Aol Instant Messenger
Publicado
2001-01-18
·
Atualizado
2008-09-05
·
CVE-2001-1416
CVSS v2.0
5.1
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AOL Instant Messenger (AIM) version 4.4
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities in log messages within certain Alpha versions of the software. These vulnerabilities allow remote attackers to execute arbitrary web script or HTML via images in the
DATA, STYLE, or BINARY tags.Recommendations
For AOL Instant Messenger (AIM) version 4.4, update to a version that addresses these XSS vulnerabilities to prevent remote attackers from executing arbitrary web scripts.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Aol Instant Messenger