PT-2014-4562 · Telerik · Telerik Ui For Asp.Net Ajax

CVE-2014-2217

·

Publicado

2014-12-25

·

Atualizado

2025-06-30

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Telerik UI for ASP.NET AJAX versions prior to Q3 2012 SP2
Description The issue allows remote attackers to write to arbitrary files and consequently execute arbitrary code via a full pathname in the UploadID metadata value in the RadAsyncUpload control.
Recommendations For versions prior to Q3 2012 SP2, update to Q3 2012 SP2 or later to resolve the issue.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-2217

Produtos afetados

Telerik Ui For Asp.Net Ajax