Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2004-0204
Description:Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.
Test IDs: 1.3.6.1.4.1.25623.1.0.12271   1.3.6.1.4.1.25623.1.0.101004  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2004-0204
BugTraq ID: 10260
http://www.securityfocus.com/bid/10260
Bugtraq: 20040502 Crystal Reports Vulnerabilities (Google Search)
http://marc.info/?l=bugtraq&m=108360413811017&w=2
Bugtraq: 20040608 Vulnerability: Arbitrary File Access & DoS in Crystal Reports (Google Search)
http://marc.info/?l=bugtraq&m=108671836127360&w=2
Microsoft Security Bulletin: MS04-017
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-017
http://www.osvdb.org/6748
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1157
http://secunia.com/advisories/11800
XForce ISS Database: crystalreports-file-deletion(16044)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16044




© 1998-2025 E-Soft Inc. All rights reserved.