← All CVEs

CVE-2004-0204

high · 7.5

Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.

7.5
CVSS
72.4%
EPSS (exploit prob.)
99th
EPSS percentile
2004-08-06
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
beaweblogic_server8.1
beaweblogic_server8.1
beaweblogic_server8.1
beaweblogic_server8.1
beaweblogic_server8.1
beaweblogic_server8.1
beaweblogic_server8.1
beaweblogic_server8.1
beaweblogic_server8.1
borland_softwarej_builderall versions
businessobjectscrystal_enterprise9
businessobjectscrystal_enterprise10
businessobjectscrystal_enterprise_java_sdk8.5
businessobjectscrystal_enterprise_ras8.5
businessobjectscrystal_reports9
businessobjectscrystal_reports10
microsoftbusiness_solutions_crm1.2
microsoftoutlook2003
microsoftvisual_studio_.net2003

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-0204