PT-2014-4562 · Telerik · Telerik Ui For Asp.Net Ajax

Published

2014-12-25

·

Updated

2025-06-30

·

CVE-2014-2217

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Telerik UI for ASP.NET AJAX versions prior to Q3 2012 SP2
Description The issue allows remote attackers to write to arbitrary files and consequently execute arbitrary code via a full pathname in the UploadID metadata value in the RadAsyncUpload control.
Recommendations For versions prior to Q3 2012 SP2, update to Q3 2012 SP2 or later to resolve the issue.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2014-2217

Affected Products

Telerik Ui For Asp.Net Ajax