vendor:
DevExpress ASPxFileManager Control for WebForms and MVC
by:
RedTeam Pentesting
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: DevExpress ASPxFileManager Control for WebForms and MVC
Affected Version From: v10.2
Affected Version To: v13.2.8
Patch Exists: YES
Related CWE: CVE-2014-2575
CPE: DEVEXPRESS:ASPXFILEMANAGER
Platforms Tested:
2014
Directory Traversal in DevExpress ASP.NET File Manager
Attackers are able to read arbitrary files by specifying a relative path.
Mitigation:
Upgrade to DevExpress ASPxFileManager v13.2.9