Security Advisory

CVE-2007-3833

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-07-17 22:00:00
Last updated 2024-08-07 14:28:52
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The AOL Instant Messenger (AIM) protocol handler in Cerulean Studios Trillian allows remote attackers to create files with arbitrary contents via certain aim: URIs, as demonstrated by a URI that begins with the "aim: &c:\" substring and contains a full pathname in the ini field. NOTE: this can be leveraged for code execution by writing to a Startup folder.