Tenable Network Security
Solutions Products Nessus Demos Partners Online Store
Nessus
Download
Plugins
     Newest Plugins
     Obtain an activation code
     View all plugins
     Search
Documentation
Register
Buy Now
ProfessionalFeed Support
Bugs
All the Tenable Products

MS04-017: Crystal Reports Web Viewer Could Allow Information Disclosure and DoS (842689) (uncredentialed check)

This script is Copyright (C) 2004-2010 Tenable Network Security, Inc.

FamilyCGI abuses
Nessus Plugin ID12271 (crystal_reports_directory_traversal.nasl)
Bugtraq ID10260
CVE IDCVE-2004-0204

Description:
Synopsis :

The web application running on the remote host has a directory
traversal vulnerability.

Description :

The remote host is running a version of Crystal Report Web interface
that is vulnerable to a remote directory traversal attack. An
attacker exploiting this issue would be able to read or delete
arbitrary files outside of the web root.

See also :

http://www.microsoft.com/technet/security/bulletin/MS04-017.mspx

Solution :

Upgrade the software or utilize ACLs on the virtual directory.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
About Us | Jobs | Whitepapers | Training | Discussion Forums | Support Portal | Blog | RSS Feeds | Contact Us | Legal | Privacy

© Copyright 2002 - 2010 Tenable Network Security(R). All Rights Reserved.

This is the web site for the Nessus Vulnerability Scanner from Tenable Network Security. If you are looking for the probabilistic analysis software from Southwest Research Institute, please visit www.nessus.swri.org