>> Interwoven WorkSite Web TransferCtrl ActiveX Remote Vulnerabilities
Title : Interwoven WorkSite Web TransferCtrl ActiveX Remote Vulnerabilities VUPEN ID : VUPEN/ADV-2008-1134 CVE ID : CVE-2008-1617 - CVE-2008-1700
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-08
Technical Description
Multiple vulnerabilities have been identified in Interwoven WorkSite, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. These issues are caused by input validation and double free errors in the Web TransferCtrl Class ActiveX control when processing overly long or malformed arguments passed to certain methods or properties (e.g. "Server"), which could be exploited by remote attackers to crash an affected browser or execute arbitrary code by tricking a user into visiting a specially crafted web page.