Back
CVE-2002-2169
Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activities, such as adding buddies and groups to a user's buddy list, via a URL with a META HTTP-EQUIV="refresh" tag to an aim: URL.
Published: Dec 31, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| aol | instant_messenger | 4.5 |
| aol | instant_messenger | 4.7 |
| aol | instant_messenger | 4.7.2480 |
GitHub Security Advisory GHSA-p3ww-q6x5-94x9
Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows...
References (8)
- http://online.securityfocus.com/archive/1/282443
- http://www.iss.net/security_center/static/9616.php
- http://www.mindflip.org/aim.html Exploit
- http://www.securityfocus.com/bid/5246 Exploit, Patch
- http://online.securityfocus.com/archive/1/282443
- http://www.iss.net/security_center/static/9616.php
- http://www.mindflip.org/aim.html Exploit
- http://www.securityfocus.com/bid/5246 Exploit, Patch
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
2.38%
Top 18% most likely to be exploited
Threat Score
20.7 / 100
Data Sources
NVD
EPSS
GitHub