CVE-2001-1464

Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.
References
Link Resource
http://www.kb.cert.org/vuls/id/403307 Exploit Third Party Advisory US Government Resource
https://exchange.xforce.ibmcloud.com/vulnerabilities/7928
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:businessobjects:crystal_reports:*:*:*:*:*:*:*:*

Information

Published : 2001-01-09 21:00

Updated : 2017-07-10 18:29


NVD link : CVE-2001-1464

Mitre link : CVE-2001-1464


JSON object : View

Advertisement

dedicated server usa

Products Affected

businessobjects

  • crystal_reports