# N/A
## 漏洞概述
Telerik.UI for ASP.NET AJAX和Sitefinity中的Telerik.Web.UI.dll存在漏洞,导致Telerik.Web.UI.DialogParametersEncryptionKey或MachineKey保护不足,远程攻击者可以利用这一缺陷泄露MachineKey,进行任意文件上传或下载、XSS攻击或ASP.NET ViewState篡改。
## 影响版本
- Progress Telerik UI for ASP.NET AJAX 早期于R2 2017 SP1版本
- Sitefinity 早期于10.0.6412.0版本
## 漏洞细节
该漏洞涉及Telerik.Web.UI.dll中的Telerik.Web.UI.DialogParametersEncryptionKey和MachineKey保护不足,导致远程攻击者能够绕过加密保护机制。
## 漏洞影响
- Leaks MachineKey
- 允许任意文件上传或下载
- 导致XSS攻击
- 使ASP.NET ViewState被篡改
# | POC 描述 | 源链接 | 神龙链接 |
---|---|---|---|
1 | Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler) | https://github.com/bao7uo/dp_crypto | POC详情 |
2 | A Burp extension to detect and exploit versions of Telerik Web UI vulnerable to CVE-2017-9248. | https://github.com/capt-meelo/Telewreck | POC详情 |
3 | None | https://github.com/ictnamanh/CVE-2017-9248 | POC详情 |
4 | PoC exploit for Telerik-CVE-2017-9248 | https://github.com/ZhenwarX/Telerik-CVE-2017-9248-PoC | POC详情 |
5 | Exploit CVE-2017-9248 Telerik ReMix from Paul Taylor's script. Exploit Telerik lastest version fixed vuln. ReMix by TinoKa & Shaco JX | https://github.com/oldboysonnt/dp | POC详情 |
6 | Another tool for exploiting CVE-2017-9248, a cryptographic weakness in Telerik UI for ASP.NET AJAX dialog handler. | https://github.com/blacklanternsecurity/dp_cryptomg | POC详情 |
7 | Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler) | https://github.com/cehamod/UI_CVE-2017-9248 | POC详情 |
8 | None | https://github.com/hlong12042/CVE-2017-9248 | POC详情 |
9 | Telerik CVE-2017-9248 Vulnerability Scanner | https://github.com/0xsharz/telerik-scanner-cve-2017-9248 | POC详情 |
暂无评论