First published: Thu Jan 18 2001(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the log messages in certain Alpha versions of AOL Instant Messenger (AIM) 4.4 allow remote attackers to execute arbitrary web script or HTML via an image in the (1) DATA, (2) STYLE, or (3) BINARY tags.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AOL AIM Triton | =4.4a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2001-1416 is considered to be medium, as it allows remote attackers to execute arbitrary web scripts through XSS vulnerabilities.
To fix CVE-2001-1416, upgrade to a non-vulnerable version of AOL Instant Messenger, as this issue has been addressed in later releases.
CVE-2001-1416 involves XSS vulnerabilities related to the DATA, STYLE, and BINARY tags used in log messages.
Users running version 4.4a of AOL Instant Messenger are affected by the vulnerabilities detailed in CVE-2001-1416.
Attackers exploiting CVE-2001-1416 can execute arbitrary web scripts or HTML, potentially leading to phishing or other malicious activities.