This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Telerik First view 2014-12-25
Product Ui For Asp.Net Ajax Last view 2019-12-11
Version * Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:telerik:ui_for_asp.net_ajax

Activity : Overall

Related : CVE

  Date Alert Description
9.8 2019-12-11 CVE-2019-18935

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)

9.8 2017-08-23 CVE-2017-11357

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

9.8 2017-08-23 CVE-2017-11317

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

9.8 2017-07-03 CVE-2017-9248

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.

7.5 2014-12-25 CVE-2014-2217

Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via a full pathname in the UploadID metadata value.

CWE : Common Weakness Enumeration

%idName
20% (1) CWE-522 Insufficiently Protected Credentials
20% (1) CWE-502 Deserialization of Untrusted Data
20% (1) CWE-326 Inadequate Encryption Strength
20% (1) CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path ...
20% (1) CWE-20 Improper Input Validation

Snort® IPS/IDS

Date Description
2019-10-08 Telerik UI cryptographic keys disclosure attempt
RuleID : 51418 - Type : SERVER-WEBAPP - Revision : 2
2019-10-08 Telerik UI cryptographic keys disclosure attempt
RuleID : 51417 - Type : POLICY-OTHER - Revision : 2
2019-10-01 Progress Telerik UI for ASP.NET AJAX arbitrary file upload attempt
RuleID : 51377 - Type : POLICY-OTHER - Revision : 4

Nessus® Vulnerability Scanner

id Description
2017-06-30 Name: A web application development suite installed on the Windows remote host is a...
File: telerik_ui_for_aspnet_ajax_CVE-2017-9248.nasl - Type: ACT_GATHER_INFO