CVE-2004-0204
highCVSS v3 Base Score
7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS Score
75.4%
Exploitation probability in 30 days
Top 1% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
P
Availability
P
Published: August 6, 2004 (7951 days ago)
Last Modified: April 16, 2026
Vendor: Microsoft
Source: NVD
Vulnerability Report
Generated by CyberWatcher
Description
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.
CWE
NVD-CWE-OtherAffected Products
bea weblogic serverborland software j builderbusinessobjects crystal enterprisebusinessobjects crystal enterprise java sdkbusinessobjects crystal enterprise rasbusinessobjects crystal reportsmicrosoft business solutions crmmicrosoft outlookmicrosoft visual studio .net