CVE-2007-4901
Summary
| CVE | CVE-2007-4901 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-09-14 18:17:00 UTC |
| Updated | 2018-10-15 21:38:00 UTC |
| Description | The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.1.41.2 and 6.2.32.1, AIM Pro, and AIM Lite does not properly constrain the use of mshtml.dll's web script and HTML functionality for incoming instant messages, which allows remote attackers to place HTML into unexpected contexts or execute arbitrary code, as demonstrated by writing arbitrary HTML to a notification window, and writing contents of arbitrary local image files to this window via IMG SRC. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Aol | Aim Lite | All | All | All | All |
| Application | Aol | Aim Lite | All | All | All | All |
| Application | Aol | Aim Pro | All | All | All | All |
| Application | Aol | Aim Pro | All | All | All | All |
| Application | Aol | Instant Messenger | 6.2.32.1 | All | All | All |
| Application | Aol | Instant Messenger | 6.2.32.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Core Security | CoreLabs | MISC | www.coresecurity.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| AOL Instant Messenger Notification Window Remote Script Code Execution Vulnerability | BID | www.securityfocus.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SecurityReason - AIM Arbitrary HTML Display in Notification Window | SREASON | securityreason.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| AOL Instant Messenger Script Execution Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | |
| Aviv Raff On .NET - Ready, AIM, fire! | MISC | aviv.raffon.net | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.