{"id":5931,"date":"2015-09-03T07:48:00","date_gmt":"2015-09-03T07:48:00","guid":{"rendered":"https:\/\/blogs.msdn.microsoft.com\/webdev\/2015\/09\/03\/ajax-control-toolkit-critical-update\/"},"modified":"2015-09-03T07:48:00","modified_gmt":"2015-09-03T07:48:00","slug":"ajax-control-toolkit-critical-update","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/dotnet\/ajax-control-toolkit-critical-update\/","title":{"rendered":"AJAX Control Toolkit Critical Update"},"content":{"rendered":"<p>Our friends at DevExpress have been hard at work on the AJAX Control toolkit and have an update available that should be installed to cover a <a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2015-4670\">critical security vulnerability<\/a> that has existed prior to the v15.1.x version.<\/p>\n<p>Brian Cardinale discovered the security vulnerability, a directory traversal issue, and has a <a href=\"http:\/\/www.cardinaleconcepts.com\/cve-2015-4670-directory-traversal-to-remote-code-execution-in-ajaxcontroltoolkit\/\">blog post<\/a> describing the issue in more detail.<\/p>\n<p>Read more on the DexExpress blog: <a href=\"https:\/\/na01.safelinks.protection.outlook.com\/?url=https%3a%2f%2fcommunity.devexpress.com%2fblogs%2faspnet%2farchive%2f2015%2f08%2f31%2fupdate-ajax-control-toolkit-to-patch-critical-security-vulnerability.aspx&amp;data=01%7c01%7cjefritz%40microsoft.com%7c5348fa4c06194a477b1108d2b4848215%7c72f988bf86f141af91ab2d7cd011db47%7c1&amp;sdata=tD%2fZO7LxMg29550dKNDSg8t4w%2bwrgXbP3H1mvVre1Vk%3d\">https:\/\/community.devexpress.com\/blogs\/aspnet\/archive\/2015\/08\/31\/update-ajax-control-toolkit-to-patch-critical-security-vulnerability.aspx<\/a><\/p>\n<p><a href=\"https:\/\/go.devexpress.com\/AjaxControlToolkit_Website_Download.aspx\">Download an installer<\/a> for the latest version of the toolkit now.<\/p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Our friends at DevExpress have been hard at work on the AJAX Control toolkit and have an update available that should be installed to cover a critical security vulnerability that has existed prior to the v15.1.x version. Brian Cardinale discovered the security vulnerability, a directory traversal issue, and has a blog post describing the issue [&hellip;]<\/p>\n","protected":false},"author":405,"featured_media":58792,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[197],"tags":[7279,30],"class_list":["post-5931","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aspnet","tag-ajax","tag-announcement"],"acf":[],"blog_post_summary":"<p>Our friends at DevExpress have been hard at work on the AJAX Control toolkit and have an update available that should be installed to cover a critical security vulnerability that has existed prior to the v15.1.x version. Brian Cardinale discovered the security vulnerability, a directory traversal issue, and has a blog post describing the issue [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/posts\/5931","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/users\/405"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/comments?post=5931"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/posts\/5931\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/media\/58792"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/media?parent=5931"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/categories?post=5931"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/tags?post=5931"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}