First published: Tue Aug 18 2015(Updated: )
Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers to write to arbitrary files via a .. (dot dot) in the fileId parameter to AjaxFileUploadHandler.axd.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DevExpress AJAX Control Toolkit | <=15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4670 is considered a critical vulnerability as it allows remote attackers to perform directory traversal attacks.
To fix CVE-2015-4670, update the DevExpress AJAX Control Toolkit to version 15.1 or later.
CVE-2015-4670 can be exploited to write arbitrary files on the server, potentially leading to remote code execution.
CVE-2015-4670 affects all versions of DevExpress AJAX Control Toolkit prior to 15.1.
The vulnerable file involved in CVE-2015-4670 is AjaxFileUploadHandler.axd.