3.4.13
11 years ago
3 years ago
Known vulnerabilities in the total.js package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version | 
|---|---|
| 
 total.js is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. It can be used as web, desktop, service or IoT application. Affected versions of this package are vulnerable to Arbitrary Code Execution via the  PoC by Alessio Della LiberaNOTE: This vulnerability has also been identified as: CVE-2021-32831 How to fix Arbitrary Code Execution? Upgrade  | <3.4.9 | 
| 
 total.js is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. It can be used as web, desktop, service or IoT application. Affected versions of this package are vulnerable to Arbitrary Code Execution via the  PoC by Alessio Della LiberaNOTE: This vulnerability has also been identified as: CVE-2021-23389 How to fix Arbitrary Code Execution? Upgrade  | <3.4.9 | 
| 
 total.js is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. It can be used as web, desktop, service or IoT application. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via  How to fix Cross-site Scripting (XSS)? Upgrade  | <3.3.0-13 | 
| 
 total.js is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. It can be used as web, desktop, service or IoT application. Affected versions of this package are vulnerable to Remote Code Execution (RCE) via  PoCHow to fix Remote Code Execution (RCE)? Upgrade  | <3.4.8 | 
| 
 total.js is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. It can be used as web, desktop, service or IoT application. Affected versions of this package are vulnerable to Prototype Pollution. The  PoCHow to fix Prototype Pollution? Upgrade  | <3.4.7 | 
| 
 total.js is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. It can be used as web, desktop, service or IoT application. Affected versions of this package are vulnerable to Command Injection. The issue occurs in the  PoCHow to fix Command Injection? Upgrade  | <3.4.7 | 
| 
 total.js is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. It can be used as web, desktop, service or IoT application. Affected versions of this package are vulnerable to Directory Traversal due to  How to fix Directory Traversal? Upgrade  | <3.3.3 | 
| 
 total.js is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. It can be used as web, desktop, service or IoT application. Affected versions of this package are vulnerable to Directory Traversal
via the  An attacker can include file contents from outside the /public directory (the default directory for accessible static files). The vulnerability is mitigated by only having a list of many extension that are triggering the file read (that's why for example, an attacker will not be able to read the content of  Note: The first two commits are attempts to fix the vulnerability, and the third one actually fixes. How to fix Directory Traversal? Upgrade  | >=2.1.0 <2.1.1>=2.2.0 <2.2.1>=2.3.0 <2.3.1>=2.4.0 <2.4.1>=2.5.0 <2.5.1>=2.6.0 <2.6.3>=2.7.0 <2.7.1>=2.8.0 <2.8.1>=2.9.0 <2.9.5>=3.0.0 <3.0.1>=3.1.0 <3.1.1>=3.2.0 <3.2.4 |