7.1
CVE-2008-1700
- EPSS 1.31%
- Veröffentlicht 08.04.2008 18:05:00
- Zuletzt bearbeitet 16.06.2026 22:52:19
- CVE-Watchlists
- Unerledigt
The Web TransferCtrl Class 8,2,1,4 (iManFile.cab), as used in WorkSite Web 8.2 before SP1 P2, allows remote attackers to cause a denial of service (memory consumption) via a large number of SendNrlLink directives, which opens a separate window for each directive.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Interwoven ≫ Worksite Web Version <= 8.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.31% | 0.669 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.1 | 8.6 | 6.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:C
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
http://www.mwrinfosecurity.com/publications/mwri_interwoven-worksite-activex-control-remote-code-execution_2008-03-10.pdf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41757