Security Advisory

CVE-2007-3833

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2007-07-17 22:00:00
Last updated 2024-08-07 14:28:52
Assigner mitre
State PUBLISHED

Description

The AOL Instant Messenger (AIM) protocol handler in Cerulean Studios Trillian allows remote attackers to create files with arbitrary contents via certain aim: URIs, as demonstrated by a URI that begins with the "aim: &c:" substring and contains a full pathname in the ini field. NOTE: this can be leveraged for code execution by writing to a Startup folder.