Title : AOL Instant Messenger File Transfer Feature Remote Directory Traversal Vulnerability VUPEN ID : VUPEN/ADV-2007-1307 CVE ID : CVE-2007-1904
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-04-10
Technical Description
A vulnerability has been identified in AOL Instant Messenger, which could be exploited by attackers to bypass security restrictions and potentially execute arbitrary commands. This issue is caused by an input validation error within the file transfer feature that does not validate filenames, which could be exploited by attackers to save malicious files to arbitrary locations by tricking a user into accepting a file transfer.