CVE-2015-4670
18.08.2015, 17:59
Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers to write to arbitrary files via a .. (dot dot) in the fileId parameter to AjaxFileUploadHandler.axd.
Vendor | Product | Version |
---|---|---|
devexpress | ajax_control_toolkit | 𝑥 ≤ 15.0 |
𝑥
= Vulnerable software versions
References