Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute arbitrary code via a crafted CSV file that is accessed through the Import CSV File menu.
References
Link Resource
https://blog.spentera.id/zahir-accounting-enterprise-plus-6/ Exploit Third Party Advisory
https://www.exploit-db.com/exploits/45505/ Exploit Third Party Advisory VDB Entry
https://www.exploit-db.com/exploits/45560/ Exploit Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-10-03T20:00:00

Updated: 2018-10-10T09:57:01

Reserved: 2018-09-23T00:00:00


Link: CVE-2018-17408

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-10-03T20:29:07.957

Modified: 2020-08-24T17:37:01.140


Link: CVE-2018-17408

JSON object: View

cve-icon Redhat Information

No data.

CWE