CVE-2004-2742: XSS
Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitrary web script or HTML via script in the URL to a report (RPT) file.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2742?
CVE-2004-2742 has a medium severity rating as it allows for cross-site scripting attacks which can compromise user data.
How do I fix CVE-2004-2742?
To fix CVE-2004-2742, upgrade your Crystal Enterprise to a patched version that addresses the XSS vulnerability.
Who is affected by CVE-2004-2742?
CVE-2004-2742 affects users of SAP BusinessObjects Crystal Enterprise versions 8.5, 9, and 10 across multiple operating systems.
What types of attacks can occur due to CVE-2004-2742?
CVE-2004-2742 can be exploited to perform cross-site scripting attacks, potentially allowing the attacker to steal session cookies or redirect users.
Is CVE-2004-2742 a remote vulnerability?
Yes, CVE-2004-2742 is a remote vulnerability that can be exploited by attackers over the internet.