>> IBM eGatherer ActiveX Control "RunEgatherer" Method Remote Code Execution Vulnerability
Title : IBM eGatherer ActiveX Control "RunEgatherer" Method Remote Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2006-3305 CVE ID : CVE-2006-4221
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-08-17
Technical Description
A vulnerability has been identified in IBM eGatherer ActiveX Control, which could be exploited by remote attackers to take complete control of an affected system. This flaw is due to a buffer overflow error when processing an overly long argument passed to the "RunEgatherer" method, which could be exploited by attackers to cause a denial of service or execute arbitrary commands by tricking a user into visiting a specially crafted web page.