CVE-2008-1617

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
08/04/2008
Last modified:
09/04/2025

Description

Double free vulnerability in Web TransferCtrl Class 8,2,1,4 (iManFile.cab), as used in WorkSite Web 8.2 before SP1 P2, allows remote attackers to execute arbitrary code via JavaScript that sets the Server property to a string, then sets the string to null.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:interwoven:worksite_web:*:*:*:*:*:*:*:* 8.2 (including)