← Back

CVE-2012-2421

nvd nist
Published: Apr 25, 2012Modified: Apr 29, 2026

JSON object

Loading...
1.8
Vector
AV:A/AC:H/Au:N/C:P/I:N/A:N
Exploitability: 3.2 / Impact: 2.9
Source: NVD

Description

Absolute path traversal vulnerability in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, might allow remote attackers to read arbitrary files in ZIP archives via a full pathname in the URI.

Affected (4)

Products: Intuit: Quickbooks
1 product
Quickbooks
Configuration A
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Intuit
Version 2009
Version 2010
Version 2011
Version 2012
Running on/withPlatform Versions
Microsoft
Internet Explorer
All versions

References (6)

Source: cve@mitre.org
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.