← Back

CVE-2014-2217

nvd nist
Published: Dec 25, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via a full pathname in the UploadID metadata value.

Affected (1)

1 product
Telerik Ui For Asp.net Ajax
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2014.3.1209

References (2)

Timeline

No history available yet.