Back to search
CVE-2004-0204
Published: Jun 11, 2004
Modified: Aug 8, 2024
PUBLISHED
Description
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20040502 Crystal Reports Vulnerabilities
mailing-list
x_refsource_BUGTRAQ
11800
third-party-advisory
x_refsource_SECUNIA
20040608 Vulnerability: Arbitrary File Access & DoS in Crystal Reports
mailing-list
x_refsource_BUGTRAQ
crystalreports-file-deletion(16044)
vdb-entry
x_refsource_XF
6748
vdb-entry
x_refsource_OSVDB
10260
vdb-entry
x_refsource_BID
oval:org.mitre.oval:def:1157
vdb-entry
signature
x_refsource_OVAL
MS04-017
vendor-advisory
x_refsource_MS
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now