Web Hack List

Collected research

Telerik Revisited

Re-examines CVE-2017-11317 in Telerik UI for ASP.NET and finds it is more than an arbitrary file upload: the rauPostData blob carries an assembly-qualified type name handed to JavaScriptSerializer, giving arbitrary deserialization. Using AssemblyInstaller to load a mixed-mode DLL runs its DllMain, so unauthenticated code execution needs no write access to the web root.

Record

Researcher
Markus Wulftange
Published by
Code White
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Markus Wulftange, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .