6.5
CVSSv3

CVE-2021-40964

Published: 15/09/2021 Updated: 19/05/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows malicious users to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter containing path traversal strings (../ and ..\) in order to escape the server's intended working directory and write malicious files onto any directory on the computer.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tinyfilemanager project tinyfilemanager

Exploits

Tiny File Manager version 246 suffers from an authenticated remote shell upload vulnerability ...

Github Repositories

Git Repository for my Bachelor Thesis "Analysis of attack vectors for embedded Linux"

Analysis of attack vectors for embedded Linux Git Repository for my Bachelor Thesis "Analysis of attack vectors for embedded Linux" The goal of this bachelor thesis was to create a training course that would give developers a brief insight into how quickly security vulnerabilities can sometimes be exploited Unpatched systems can often be very easily taken over or cri