Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, might allow remote attackers to obtain sensitive information via a URI with a % (percent) character as its (1) last or (2) second-to-last character, in situations where a certain "post-URL data" buffer contains a 0x0000 character but a buffer overflow does not occur.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Intuit QuickBooks ‘HelpAsyncPluggableProtocol.dll’ 路径遍历漏洞
Vulnerability Description
Intuit QuickBooks 2009至2012版本中的HelpAsyncPluggableProtocol.dll中的intu-help-qb (也称Intuit Help System Async Pluggable Protocol) handlers中存在绝对路径遍历漏洞。当使用Internet Explorer时,远程攻击者可利用该漏洞借助一个以%(百分号)字符为它的(1)最后一个或者(2)第二个到最后一个字符,在某个“post-URL”缓冲区包含0x0000字符但不会出现缓冲区溢出的情况
CVSS Information
N/A
Vulnerability Type
N/A