Multiple cross-site scripting (XSS) vulnerabilities in the log messages in certain Alpha versions of AOL Instant Messenger (AIM) 4.4 allow remote attackers to execute arbitrary web script or HTML via an image in the (1) DATA, (2) STYLE, or (3) BINARY tags.
References
Link | Resource |
---|---|
http://www.windowsitpro.com/Articles/Index.cfm?ArticleID=19811&DisplayTab=Article | |
http://www.kb.cert.org/vuls/id/JARL-56TPBQ | US Government Resource |
http://www.kb.cert.org/vuls/id/541384 | US Government Resource |
Configurations
Information
Published : 2001-01-17 21:00
Updated : 2008-09-05 13:26
NVD link : CVE-2001-1416
Mitre link : CVE-2001-1416
JSON object : View
CWE
Products Affected
aol
- instant_messenger