Unrated severityNVD Advisory· Published Sep 5, 2007· Updated Apr 23, 2026
CVE-2007-4471
CVE-2007-4471
Description
Multiple unspecified vulnerabilities in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to create or overwrite arbitrary files via unspecified arguments to the (1) httpGETToFile, (2) httpPOSTFromFile, and possibly other methods, probably involving path traversal vulnerabilities in exposed dangerous methods. NOTE: this can be leveraged for code execution by writing to a Startup folder.
Affected products
1- cpe:2.3:a:intuit:quickbooks:*:*:online:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.kb.cert.org/vuls/id/979638nvdPatchThird Party AdvisoryUS Government Resource
- osvdb.org/37134nvd
- secunia.com/advisories/26659nvd
- www.securityfocus.com/bid/25544nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/36464nvd
News mentions
0No linked articles in our index yet.