|
|
|
|
|
|
|
| |
MS04-017: Crystal Reports Web Viewer Could Allow Information Disclosure and DoS (842689) (uncredentialed check) |
|
| This script is Copyright (C) 2004-2010 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses |
| Nessus Plugin ID | 12271 (crystal_reports_directory_traversal.nasl) |
| Bugtraq ID | 10260
|
| CVE ID | CVE-2004-0204
|
|
| Description: |
Synopsis :
The web application running on the remote host has a directory
traversal vulnerability.
Description :
The remote host is running a version of Crystal Report Web interface
that is vulnerable to a remote directory traversal attack. An
attacker exploiting this issue would be able to read or delete
arbitrary files outside of the web root.
See also :
http://www.microsoft.com/technet/security/bulletin/MS04-017.mspx
Solution :
Upgrade the software or utilize ACLs on the virtual directory.
Risk factor :
High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
|
|
|
|
|
|