Sorry for the brief post but Im still able to bypass filters that aol has put in place. So again with frustration I come to FD to imply pressure on a company to patch correct. From reading feedback from AOL they feel the vulnerability is put to bed and requires no more attention.
I am not posting 0day PoC only currently patched examples.
Do not use any AIM 6 or higher client.
old PoC
http://before0day.com/Lists/Posts/Post.aspx?ID=3
references
http://www.wired.com/politics/security/news/2007/12/aim_hack
http://www.pronetworks.org/index.php/software-and-betas-news/847#comment-199
Michael Evanchik
http://before0day.com