>> WebEx ActiveX Control Components Download Remote Code Execution Vulnerability
Title : WebEx ActiveX Control Components Download Remote Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2006-2688 CVE ID : CVE-2006-3423 - CVE-2006-3424
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-07-06
Technical Description
A vulnerability has been identified in WebEx ActiveX Control, which could be exploited by remote attackers to take complete control of an affected system. This flaw is due to input validation errors when handling the "GpcUrlRoot" and "GpcIniFileName" parameters, which could be exploited by remote attackers to download and execute malicious components by tricking a user into visiting a specially crafted web page.
Note : Various buffer overflow errors have also been identified in certain versions of the ActiveX control, which could be exploited by malicious web sites to execute arbitrary commands.