Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Progress Telerik UI for ASP.NET AJAX 安全漏洞
Vulnerability Description
ASP.NET AJAX是一个用于ASP.NET的控件。Progress Telerik UI是美国Telerik公司开发的一个用于处理AJAX的ASP.NET控件的UI(用户界面)。 Progress Telerik UI for ASP.NET AJAX R2 2017 SP2之前的版本中存在安全漏洞,该漏洞源于程序没有正确的验证用户提交到RadAsyncUpload中的输入。远程攻击者可利用该漏洞上传任意文件或执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A