CVE-2014-2217: Progress Telerik UI For ASP.NET AJAX
High severity, CVSS 7.5. EPSS: 4.1% chance of exploitation in the next 30 days.
Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via a full pathname in the UploadID metadata value.
Affected products
- Progress Telerik UI For ASP.NET AJAX: up to and including 2014.3.1209
Published 2014-12-25. Last modified 2026-06-17.