CVE-2014-2575
06.06.2014, 14:55
Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter.
Vendor | Product | Version |
---|---|---|
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 𝑥 ≤ 13.1.9 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 10.2 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 10.2.3 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 10.2.4 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 10.2.5 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 10.2.6 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 10.2.8 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 10.2.9 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 10.2.10 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 10.2.11 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.1 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.1.4 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.1.5 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.1.6 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.1.7 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.1.8 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.1.9 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.1.10 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.1.11 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.1.12 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.2 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.2.5 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.2.7 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.2.8 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.2.10 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.2.11 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.2.12 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.2.13 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 11.2.14 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.1 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.1.4 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.1.5 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.1.6 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.1.7 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.1.8 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.1.9 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.1.10 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.1.11 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.1.12 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.2 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.2.4 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.2.5 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.2.6 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.2.7 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.2.8 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.2.10 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.2.11 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.2.12 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.2.13 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.2.15 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 12.2.16 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 13.1 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 13.1.4 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 13.1.5 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 13.1.6 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 13.1.7 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 13.1.8 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 13.2 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 13.2.5 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 13.2.6 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 13.2.7 |
devexpress | aspxfilemanager_control_for_webforms_and_mvc | 13.2.8 |
𝑥
= Vulnerable software versions
References