CVE-2004-0204 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 72.4% (pctl 99)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 72.37% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-08-06 |
| Last modified | 2026-06-16 |
Affected (9)
| Vendor | Product |
|---|---|
| bea | weblogic server |
| borland software | j builder |
| businessobjects | crystal enterprise |
| businessobjects | crystal enterprise java sdk |
| businessobjects | crystal enterprise ras |
| businessobjects | crystal reports |
| microsoft | business solutions crm |
| microsoft | outlook |
| microsoft | visual studio .net |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Business Objects Crystal Reports 9/10 Web Form Viewer - Directory Traversal | 2004-05-03 |
References
- http://marc.info/?l=bugtraq&m=108360413811017&w=2
- http://marc.info/?l=bugtraq&m=108671836127360&w=2
- http://secunia.com/advisories/11800
- http://support.businessobjects.com/fix/hot/critical/bulletins/security_bulletin_june04.asp
- http://www.osvdb.org/6748
- http://www.securityfocus.com/bid/10260
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-017
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16044
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1157
- http://marc.info/?l=bugtraq&m=108360413811017&w=2
- http://marc.info/?l=bugtraq&m=108671836127360&w=2
- http://secunia.com/advisories/11800
- http://support.businessobjects.com/fix/hot/critical/bulletins/security_bulletin_june04.asp
- http://www.osvdb.org/6748
- http://www.securityfocus.com/bid/10260
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-017
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16044
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1157
→ the Explorer · watch your stack · NVD