CVE-2014-2217 describes an absolute path traversal vulnerability in the RadAsyncUpload control within Telerik UI for ASP.NET AJAX versions prior to Q3 2012 SP2. This flaw allows unauthenticated remote attackers to write arbitrary files to the server by manipulating the UploadID metadata with a full pathname, which can lead to arbitrary code execution. The vulnerability has a CVSS score of 7.5 (High), indicating a low attack complexity and no authentication required, with potential impacts on confidentiality, integrity, and availability. Its EPSS score is low, suggesting a low probability of exploitation. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While there is limited community discussion and media coverage, one article links it to the Blue Mockingbird campaign, suggesting it may have been leveraged in specific attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2014.3.1209CPE matchmatch criteria | cpe:2.3:a:progress:telerik_ui_for_asp.net_ajax:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
GFI Archiver v15.7 Multiple vulnerabilities
Jun 10, 2025GFI Archiver v15.7 Multiple vulnerabilities
Jun 10, 2025GFI Archiver v15.7 Multiple vulnerabilities
Jun 10, 2025GFI Archiver v15.7 Multiple vulnerabilities
Jun 10, 2025