Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-4471

Опубликовано: 05 сент. 2007
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Multiple unspecified vulnerabilities in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to create or overwrite arbitrary files via unspecified arguments to the (1) httpGETToFile, (2) httpPOSTFromFile, and possibly other methods, probably involving path traversal vulnerabilities in exposed dangerous methods. NOTE: this can be leveraged for code execution by writing to a Startup folder.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:intuit:quickbooks:*:*:online:*:*:*:*:*

EPSS

Процентиль: 82%
0.01653
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
почти 4 года назад

Multiple unspecified vulnerabilities in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to create or overwrite arbitrary files via unspecified arguments to the (1) httpGETToFile, (2) httpPOSTFromFile, and possibly other methods, probably involving path traversal vulnerabilities in exposed dangerous methods. NOTE: this can be leveraged for code execution by writing to a Startup folder.

EPSS

Процентиль: 82%
0.01653
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-22