First published: Wed Jan 10 2001(Updated: )
Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Businessobjects Crystal Reports |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.