CVE-2014-2575
Summary
| CVE | CVE-2014-2575 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-06-06 14:55:04 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| DevExpress ASP.NET File Manager CVE-2014-2575 Directory Traversal Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Full Disclosure: [RT-SA-2014-006] Directory Traversal in DevExpress ASP.NET File Manager | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| DevExpress ASPxFileManager 10.2 < 13.2.8 - Directory Traversal | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| osvdb.org/show/osvdb/107742 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| RedTeam Pentesting GmbH - Directory Traversal in DevExpress ASP.NET File Manager | af854a3a-2127-422b-91ae-364da2661108 | www.redteam-pentesting.de | Exploit |
| security.devexpress.com/de7c4756 | af854a3a-2127-422b-91ae-364da2661108 | security.devexpress.com | Vendor Advisory |
| DevExpress ASP.NET File Manager 13.2.8 Directory Traversal ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.