DevExpress ASP.NET File Manager CVE-2014-2575 Directory Traversal Vulnerability
BID:67902
Info
DevExpress ASP.NET File Manager CVE-2014-2575 Directory Traversal Vulnerability
| Bugtraq ID: | 67902 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2575 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2014 12:00AM |
| Updated: | Jun 05 2014 12:00AM |
| Credit: | RedTeam Pentesting GmbH |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
DevExpress ASP.NET File Manager CVE-2014-2575 Directory Traversal Vulnerability
DevExpress ASP.NET File Manager is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to view arbitrary local files and directories within the context of the application. Information harvested may aid in launching further attacks.
Easytime Studio Easy File Manager 10.2 through 13.2.8 are vulnerable.
DevExpress ASP.NET File Manager is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to view arbitrary local files and directories within the context of the application. Information harvested may aid in launching further attacks.
Easytime Studio Easy File Manager 10.2 through 13.2.8 are vulnerable.
Exploit / POC
DevExpress ASP.NET File Manager CVE-2014-2575 Directory Traversal Vulnerability
Attacker can exploit this issue through a browser.
Attacker can exploit this issue through a browser.
Solution / Fix
DevExpress ASP.NET File Manager CVE-2014-2575 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
DevExpress ASP.NET File Manager CVE-2014-2575 Directory Traversal Vulnerability
References:
References: