Description
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Bea
Subscribe
Weblogic Server
Subscribe
Borland Software
Subscribe
J Builder
Subscribe
Businessobjects
Subscribe
Crystal Enterprise
Subscribe
Crystal Enterprise Java Sdk
Subscribe
Crystal Enterprise Ras
Subscribe
Crystal Reports
Subscribe
Microsoft
Subscribe
Business Solutions Crm
Subscribe
Outlook
Subscribe
Visual Studio .net
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T00:10:03.760Z
Reserved: 2004-03-11T00:00:00.000Z
Link: CVE-2004-0204
No data.
Status : Deferred
Published: 2004-08-06T04:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2004-0204
No data.
OpenCVE Enrichment
No data.
Weaknesses