Show filters
148 Total Results
Displaying 51-60 of 148
Sort by:
Attacker Value
Unknown
CVE-2021-40966
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with a malicious filename containing javascript code and it will run on any user browser when they access the server.
0
Attacker Value
Unknown
CVE-2021-40964
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter containing path traversal strings (../ and ..\) in order to escape the server's intended working directory and write malicious files onto any directory on the computer.
0
Attacker Value
Unknown
CVE-2020-28589
Disclosure Date: August 11, 2021 (last updated February 23, 2025)
An improper array index validation vulnerability exists in the LoadObj functionality of tinyobjloader v2.0-rc1 and tinyobjloader development commit 79d4421. A specially crafted file could lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-37573
Disclosure Date: August 09, 2021 (last updated February 23, 2025)
A reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS) <=1.115 allows an adversary to inject malicious code on the server's "404 Page not Found" error page
0
Attacker Value
Unknown
CVE-2020-36438
Disclosure Date: August 08, 2021 (last updated February 23, 2025)
An issue was discovered in the tiny_future crate before 0.4.0 for Rust. Future<T> does not have bounds on its Send and Sync traits.
0
Attacker Value
Unknown
CVE-2020-18428
Disclosure Date: July 26, 2021 (last updated February 23, 2025)
tinyexr commit 0.9.5 was discovered to contain an array index error in the tinyexr::SaveEXR component, which can lead to a denial of service (DOS).
0
Attacker Value
Unknown
CVE-2020-18430
Disclosure Date: July 26, 2021 (last updated February 23, 2025)
tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to a denial of service (DOS).
0
Attacker Value
Unknown
CVE-2020-19490
Disclosure Date: July 21, 2021 (last updated February 23, 2025)
tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.
0
Attacker Value
Unknown
CVE-2020-24026
Disclosure Date: May 18, 2021 (last updated February 22, 2025)
TinyShop, a free and open source mall based on RageFrame2, has a stored XSS vulnerability that affects version 1.2.0. TinyShop allows XSS via the explain_first and again_explain parameters of the /evaluate/index.php page. The vulnerability may be exploited remotely, resulting in cross-site scripting (XSS) or information disclosure.
0
Attacker Value
Unknown
CVE-2020-35884
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.
0