7.5
CVSSv2

CVE-2014-2217

Published: 25/12/2014 Updated: 29/12/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote malicious users to write to arbitrary files, and consequently execute arbitrary code, via a full pathname in the UploadID metadata value.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

telerik ui for asp.net ajax

Github Repositories

This script uses scrapy to search for Telerikwebui installations on our network and report on the version with the goal of detecting CVE-2019-18935 CVE-2017-11317 CVE-2014-2217