Web Hack List

Other nomination

Remote Code Execution via Insecure Deserialization in Telerik UI

Telerik UI for ASP.NET AJAX takes the object type from its encrypted rauPostData upload parameter and hands it to JavaScriptSerializer. After breaking the hard-coded upload encryption key and uploading a mixed mode assembly DLL, an attacker names AssemblyInstaller as the type and points its Path at that DLL, so loading it runs native code and returns a reverse shell.

Record

Researcher
Caleb Gross
Format
Advisory

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Caleb Gross, first published at the original source. Preserved copies are kept so the citation survives its host.