Back

CVE-2002-2169

Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activities, such as adding buddies and groups to a user's buddy list, via a URL with a META HTTP-EQUIV="refresh" tag to an aim: URL.

Published: Dec 31, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
aol instant_messenger 4.5
aol instant_messenger 4.7
aol instant_messenger 4.7.2480

GitHub Security Advisory GHSA-p3ww-q6x5-94x9

Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 2.38%

Top 18% most likely to be exploited

Threat Score 20.7 / 100

Data Sources

NVD EPSS GitHub