CVE-2017-11317
Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
3
*Multiple Sources
Exploited in Wild
Yes
*KEV
Decision
-
*SSVC
Descriptions
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
Telerik.Web.UI en Progress Telerik UI for ASP.NET AJAX en versiones anteriores a la R1 2017 y R2 en versiones anteriores a la R2 2017 SP2 emplea un cifrado RadAsyncUpload débil, lo que permite que atacantes remotos realicen subidas de archivos arbitrarios o ejecuten código arbitrario.
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-07-13 CVE Reserved
- 2017-08-23 CVE Published
- 2022-04-11 Exploited in Wild
- 2022-05-02 KEV Due Date
- 2024-07-18 First Exploit
- 2024-08-05 CVE Updated
- 2024-10-15 EPSS Updated
CWE
- CWE-326: Inadequate Encryption Strength
CAPEC
References (12)
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Telerik Search vendor "Telerik" | Ui For Asp.net Ajax Search vendor "Telerik" for product "Ui For Asp.net Ajax" | <= 2016.3.1027 Search vendor "Telerik" for product "Ui For Asp.net Ajax" and version " <= 2016.3.1027" | - |
Affected
| ||||||
Telerik Search vendor "Telerik" | Ui For Asp.net Ajax Search vendor "Telerik" for product "Ui For Asp.net Ajax" | 2017.2.503 Search vendor "Telerik" for product "Ui For Asp.net Ajax" and version "2017.2.503" | - |
Affected
| ||||||
Telerik Search vendor "Telerik" | Ui For Asp.net Ajax Search vendor "Telerik" for product "Ui For Asp.net Ajax" | 2017.2.621 Search vendor "Telerik" for product "Ui For Asp.net Ajax" and version "2017.2.621" | - |
Affected
|