CVE-2014-2575
Last modified
CVE-2014-2575 is a vulnerability of currently unknown severity. Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter.. EPSS estimates a 7.33% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | <= 13.1.9 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 10.2 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 10.2.3 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 10.2.4 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 10.2.5 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 10.2.6 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 10.2.8 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 10.2.9 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 10.2.10 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 10.2.11 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.1 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.1.4 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.1.5 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.1.6 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.1.7 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.1.8 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.1.9 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.1.10 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.1.11 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.1.12 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.2 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.2.5 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.2.7 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.2.8 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.2.10 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.2.11 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.2.12 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.2.13 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 11.2.14 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.1 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.1.4 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.1.5 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.1.6 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.1.7 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.1.8 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.1.9 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.1.10 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.1.11 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.1.12 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.2 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.2.4 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.2.5 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.2.6 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.2.7 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.2.8 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.2.10 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.2.11 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.2.12 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.2.13 |
| Devexpress | Aspxfilemanager Control For Webforms And Mvc | 12.2.15 |
Showing 50 of 62 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-2575?
How severe is CVE-2014-2575?
How do I fix CVE-2014-2575?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-2567The OpenConnectionTask::handleStateHelper function in Imap/T…
- CVE-2014-2568Use-after-free vulnerability in the nfqnl_zcopy function in …
- CVE-2014-2570Cross-site scripting (XSS) vulnerability in www/make_subset.…
- CVE-2014-2571Cross-site scripting (XSS) vulnerability in the quiz_questio…
- CVE-2014-2572mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does…
- CVE-2014-2573The VMWare driver in OpenStack Compute (Nova) 2013.2 through…
- CVE-2014-2576plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables th…
- CVE-2014-2577Multiple cross-site scripting (XSS) vulnerabilities in the T…
- CVE-2014-2578Cross-site scripting (XSS) vulnerability in Splunk Web in Sp…
- CVE-2014-2579Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2014-2580The netback driver in Xen, when using certain Linux versions…
- CVE-2014-2581Smb4K before 1.1.1 allows remote attackers to obtain credent…7.5
Are you affected by CVE-2014-2575?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
