vendor:
Instant Messenger
by:
skape, thief <thief@hick.org>
N/A
CVSS
N/A
SEH Overwrite
119
CWE
Product Name: Instant Messenger
Affected Version From: AOL Instant Messenger 5.5
Affected Version To: AOL Instant Messenger 5.5
Patch Exists: NO
Related CWE: CVE-2004-0636
CPE: a:aol:instant_messenger
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows NT/2000/XP/2003
2010
AOL Instant Messenger goaway Overflow
This module exploits a flaw in the handling of AOL Instant Messenger's 'goaway' URI handler. An attacker can execute arbitrary code by supplying a overly sized buffer as the 'message' parameter. This issue is known to affect AOL Instant Messenger 5.5.
Mitigation:
No known mitigation