Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolete since June 2013.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-3185 Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolete since June 2013.
Github GHSA Github GHSA GHSA-8h7p-qjv8-9mp4 Improper Access Control in Telerik Extensions
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T10:39:59.485Z

Reserved: 2018-09-15T00:00:00

Link: CVE-2018-17060

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-10-08T16:29:01.523

Modified: 2024-11-21T03:53:47.793

Link: CVE-2018-17060

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses