CVE-2007-1904

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/04/2007
Last modified:
09/04/2025

Description

Directory traversal vulnerability in AOL Instant Messenger (AIM) 5.9 and earlier, and ICQ 5.1 and probably earlier, allows user-assisted remote attackers to write files to arbitrary locations via a .. (dot dot) in a filename in a file transfer operation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:aol:icq:*:*:*:*:*:*:*:* 5.1 (including)
cpe:2.3:a:aol:instant_messenger:*:*:*:*:*:*:*:* 5.9.3861 (including)