Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Moran Surf

Pesquisador deImperva Application Defense Center
#35613de 53,641
7.5CVSS total
Vulnerabilidades · 1
PT-2004-1369
7.5
2004-06-11
Sap · Business Objects Crystal Reports · CVE-2004-0204
**Name of the Vulnerable Software and Affected Versions** Business Objects Crystal Reports versions 9 and 10 Crystal Enterprise versions 9 and 10 **Description** A directory traversal issue exists in the web viewers for the mentioned products, allowing remote attackers to read and delete arbitrary files. This is achieved by using ".." sequences in the `dynamicimag` argument to the "crystalimagehandler.aspx" API endpoint. **Recommendations** For Business Objects Crystal Reports versions 9 and 10, and Crystal Enterprise versions 9 and 10, consider restricting access to the "crystalimagehandler.aspx" API endpoint until a patch is available. As a temporary workaround, avoid using the `dynamicimag` argument in the "crystalimagehandler.aspx" API endpoint to minimize the risk of exploitation.