Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute arbitrary code via a crafted CSV file that is accessed through the Import CSV File menu.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://blog.spentera.id/zahir-accounting-enterprise-plus-6/ | third party advisory exploit |
https://www.exploit-db.com/exploits/45560/ | exploit vdb entry third party advisory |
https://www.exploit-db.com/exploits/45505/ | exploit vdb entry third party advisory |