>> IBM Lotus Domino Web Access Upload Module Remote Buffer Overflow
Title : IBM Lotus Domino Web Access Upload Module Remote Buffer Overflow VUPEN ID : VUPEN/ADV-2007-4296 CVE ID : CVE-2007-4474
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-21
Technical Description
A vulnerability has been identified in IBM Lotus Domino Web Access, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the "inotes6w.dll" and "dwa7W.dll" ActiveX controls when calling the "InstallBrowserHelperDll()" method while passing an overly long data to the "General_ServerName" property, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.