Microsoft Security Bulletin MS04-017: Vulnerability in Crystal Reports Web Viewer Could Allow Information Disclosure and Denial of Service (842689)
Microsoft Security Bulletin MS04-017: Vulnerability in Crystal Reports Web Viewer Could Allow Information Disclosure and Denial of Service (842689)07/13/2004 12:00 PM This update resolves a newly-discovered vulnerability in Crystal
Reports and Crystal Enterprise from Business Objects. Microsoft Visual
Studio .NET 2003 (all versions) and Outlook 2003 with Business Contact
Manager redistribute Crystal Reports and are therefore affected by the
vulnerability. Microsoft Business Solutions CRM 1.2 redistributes
Crystal Enterprise, which is affected in the same way. The
vulnerability is documented in the Vulnerability Details section of
this bulletin.
An attacker who successfully exploited the vulnerability could
retrieve and delete files through the Crystal Reports and Crystal
Enterprise Web viewers on an affected system. The number of files of
files that are impacted by this vulnerability would depend on the
security context of the affected component that is used by the Crystal
Web viewer.
Going Beyond FTC Paid Inclusion Disclosure Guidelines06/17/2004 04:33 PM Source: SearchDay - A look at how Yahoo might go beyond FTC guidelines
about paid inclusion as a means of rebuilding faith in the impact of
paid inclusion on relevancy and its listings in general....
Response to David Litchfield on Responsible Disclosure and Infosec Research