CVE-2012-2421
1.8
Vector
AV:A/AC:H/Au:N/C:P/I:N/A:N
Exploitability: 3.2 / Impact: 2.9
Source: NVD
Description
Absolute path traversal vulnerability in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, might allow remote attackers to read arbitrary files in ZIP archives via a full pathname in the URI.
Affected (4)
Products: Intuit: Quickbooks
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2009 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Internet Explorer | All versions |
References (6)
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.