{"api_version":"1","generated_at":"2026-07-23T07:38:27+00:00","cve":"CVE-2005-1930","urls":{"html":"https://cve.report/CVE-2005-1930","api":"https://cve.report/api/cve/CVE-2005-1930.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1930","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1930"},"summary":{"title":"CVE-2005-1930","description":"Directory traversal vulnerability in the Crystal Report component (rptserver.asp) in Trend Micro ServerProtect Management Console 5.58, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, and possibly earlier versions, allows remote attackers to read arbitrary files via the IMAGE parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-14 20:07:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2005/2907","name":"http://www.vupen.com/english/advisories/2005/2907","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/18038","name":"http://secunia.com/advisories/18038","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Trend Micro ServerProtect Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21770","name":"http://www.osvdb.org/21770","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/15867","name":"http://www.securityfocus.com/bid/15867","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Trend Micro ServerProtect RPTServer.ASP Directory Traversal Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1015358","name":"http://securitytracker.com/id?1015358","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Trend Micro ServerProtect Buffer Overflows and Other Bugs Permit Remote Code Execution, Denial of Service, and File Disclosure - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/258","name":"http://securityreason.com/securityalert/258","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Trend Micro ServerProtect Crystal Reports ReportServer File Disclosure - SecurityReason.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.idefense.com/application/poi/display?id=352&type=vulnerabilities","name":"http://www.idefense.com/application/poi/display?id=352&type=vulnerabilities","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Accenture | Let there be change","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1930","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1930","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1930","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trend_micro","cpe5":"serverprotect","cpe6":"5.58","cpe7":"*","cpe8":"emc","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:06:57.667Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"18038","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18038"},{"name":"1015358","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015358"},{"name":"15867","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15867"},{"name":"20051214 Trend Micro ServerProtect Crystal Reports ReportServer File Disclosure","tags":["third-party-advisory","x_refsource_IDEFENSE","x_transferred"],"url":"http://www.idefense.com/application/poi/display?id=352&type=vulnerabilities"},{"name":"21770","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21770"},{"name":"258","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/258"},{"name":"ADV-2005-2907","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2907"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-12-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Directory traversal vulnerability in the Crystal Report component (rptserver.asp) in Trend Micro ServerProtect Management Console 5.58, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, and possibly earlier versions, allows remote attackers to read arbitrary files via the IMAGE parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-12-20T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"18038","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18038"},{"name":"1015358","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015358"},{"name":"15867","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15867"},{"name":"20051214 Trend Micro ServerProtect Crystal Reports ReportServer File Disclosure","tags":["third-party-advisory","x_refsource_IDEFENSE"],"url":"http://www.idefense.com/application/poi/display?id=352&type=vulnerabilities"},{"name":"21770","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21770"},{"name":"258","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/258"},{"name":"ADV-2005-2907","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2907"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-1930","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Directory traversal vulnerability in the Crystal Report component (rptserver.asp) in Trend Micro ServerProtect Management Console 5.58, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, and possibly earlier versions, allows remote attackers to read arbitrary files via the IMAGE parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"18038","refsource":"SECUNIA","url":"http://secunia.com/advisories/18038"},{"name":"1015358","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015358"},{"name":"15867","refsource":"BID","url":"http://www.securityfocus.com/bid/15867"},{"name":"20051214 Trend Micro ServerProtect Crystal Reports ReportServer File Disclosure","refsource":"IDEFENSE","url":"http://www.idefense.com/application/poi/display?id=352&type=vulnerabilities"},{"name":"21770","refsource":"OSVDB","url":"http://www.osvdb.org/21770"},{"name":"258","refsource":"SREASON","url":"http://securityreason.com/securityalert/258"},{"name":"ADV-2005-2907","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2907"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-1930","datePublished":"2005-12-14T20:00:00.000Z","dateReserved":"2005-06-08T00:00:00.000Z","dateUpdated":"2024-08-07T22:06:57.667Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-14 20:07:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:trend_micro:serverprotect:5.58:*:emc:*:*:*:*:*","matchCriteriaId":"1364240C-2070-4CEA-BAE9-E94EAFFBBF1D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1930","Ordinal":"1","Title":"CVE-2005-1930","CVE":"CVE-2005-1930","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1930","Ordinal":"1","NoteData":"Directory traversal vulnerability in the Crystal Report component (rptserver.asp) in Trend Micro ServerProtect Management Console 5.58, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, and possibly earlier versions, allows remote attackers to read arbitrary files via the IMAGE parameter.","Type":"Description","Title":"CVE-2005-1930"},{"CveYear":"2005","CveId":"1930","Ordinal":"2","NoteData":"2005-12-14","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"1930","Ordinal":"3","NoteData":"2005-12-20","Type":"Other","Title":"Modified"}]}}}