PT-2005-2883 · Sap+1 · Crystal Reports+1

Publicado

2005-12-14

·

Atualizado

2011-03-08

·

CVE-2005-1930

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Trend Micro ServerProtect Management Console versions prior to 5.58
Description A directory traversal issue exists in the Crystal Report component, specifically in the rptserver.asp file, allowing remote attackers to read arbitrary files. This is achieved by manipulating the IMAGE parameter.
Recommendations For versions prior to 5.58, consider restricting access to the rptserver.asp file and the IMAGE parameter to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1930

Produtos afetados

Crystal Reports
Trend Micro Serverprotect Management Console