CVE-2008-1617
Last modified
CVE-2008-1617 is a vulnerability of currently unknown severity. Double free vulnerability in Web TransferCtrl Class 8,2,1,4 (iManFile.cab), as used in WorkSite Web 8.2 before SP1 P2, allows remote attackers to execute arbitrary code via JavaScript that sets the Server property to a string, then sets the string to null.. EPSS estimates a 4.37% chance of exploitation in the next 30 days.
Description
Double free vulnerability in Web TransferCtrl Class 8,2,1,4 (iManFile.cab), as used in WorkSite Web 8.2 before SP1 P2, allows remote attackers to execute arbitrary code via JavaScript that sets the Server property to a string, then sets the string to null.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Interwoven | Worksite Web | <= 8.2 |
References
- http://secunia.com/advisories/29733Vendor Advisory
- http://secunia.com/advisories/29733Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1617?
How severe is CVE-2008-1617?
How do I fix CVE-2008-1617?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-1610Stack-based buffer overflow in TallSoft Quick TFTP Server Pr…
- CVE-2008-1611Stack-based buffer overflow in TFTP Server SP 1.4 for Window…
- CVE-2008-1612The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17…
- CVE-2008-1613SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Bu…
- CVE-2008-1614suPHP before 0.6.3 allows local users to gain privileges via…
- CVE-2008-1615Linux kernel 2.6.18, and possibly other versions, when runni…
- CVE-2008-1618The PPTP VPN service in Watchguard Firebox before 10, when p…
- CVE-2008-1619The ssm_i emulation in Xen 5.1 on IA64 architectures allows …
- CVE-2008-1620Directory traversal vulnerability in 2X TFTP service (TFTPd.…
- CVE-2008-1621Multiple cross-site scripting (XSS) vulnerabilities in GeeCa…
- CVE-2008-1622Multiple PHP remote file inclusion vulnerabilities in GeeCar…
- CVE-2008-1623SQL injection vulnerability in admin_view_image.php in Smoot…
Are you affected by CVE-2008-1617?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
