VulnerabilityModified
CVE-2002-1813
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8.2790 allows remote attackers to execute arbitrary programs by specifying the program in the href attribute of a link.
LOW 2.6EPSS 6.87%
Does this matter?
Lower severity and a low EPSS score (6.87%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8.2790 allows remote attackers to execute arbitrary programs by specifying the program in the href attribute of a link.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
- EPSS
- 6.87% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- aol/instant messenger
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0319.htmlExploit, Vendor Advisory
- http://www.iss.net/security_center/static/10441.phpPatch
- http://www.securityfocus.com/bid/6027Exploit
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0319.htmlExploit, Vendor Advisory
- http://www.iss.net/security_center/static/10441.phpPatch
- http://www.securityfocus.com/bid/6027Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.