Записи etherpad
19 опубликованных записей вендора etherpad.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 10,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-790 Improper Filtering of Special Elements1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
19 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2018-9845Proof of concept | Etherpad Lite before 1.6.4 is exploitable for admin access.etherpad · etherpad lite · CWE-178 | Критическая9,8 | — | 12,9 % | 29 апр. 2018 г. |
40В плане | CVE-2018-6835Эксплойта нет | node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restetherpad · etherpad · CWE-20 | Критическая9,8 | — | 2,3 % | 8 февр. 2018 г. |
40В плане | CVE-2018-9326Эксплойта нет | Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.etherpad · etherpad | Критическая9,8 | — | 2,0 % | 7 апр. 2018 г. |
36Наблюдать | CVE-2021-43802Эксплойта нет | Admin privilege escalation and arbitrary code execution via malicious *.etherpad importsetherpad · etherpad · CWE-790 | Высокая8,8 | — | 2,1 % | 9 дек. 2021 г. |
32Наблюдать | CVE-2018-9327Эксплойта нет | Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server.etherpad · etherpad · CWE-20 | Высокая8,1 | — | 1,6 % | 7 апр. 2018 г. |
31Наблюдать | CVE-2015-3297Эксплойта нет | Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files byetherpad · etherpad · CWE-22 | Высокая7,5 | — | 5,0 % | 7 июл. 2017 г. |
31Наблюдать | CVE-2015-2298Эксплойта нет | node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an imetherpad · etherpad · CWE-200 | Высокая7,5 | — | 2,3 % | 12 янв. 2018 г. |
31Наблюдать | CVE-2015-4085Эксплойта нет | Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.etherpad · etherpad · CWE-22 | Высокая7,5 | — | 2,3 % | 7 сент. 2017 г. |
31Наблюдать | CVE-2015-3309Эксплойта нет | Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files wietherpad · etherpad · CWE-22 | Высокая7,5 | — | 2,3 % | 13 февр. 2020 г. |
30Наблюдать | CVE-2018-9325Эксплойта нет | Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.etherpad · etherpad · CWE-200 | Высокая7,5 | — | 1,2 % | 7 апр. 2018 г. |
30Наблюдать | CVE-2020-22781Эксплойта нет | In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash etherpad · etherpad · CWE-89 | Высокая7,5 | — | 1,1 % | 28 апр. 2021 г. |
30Наблюдать | CVE-2020-22782Эксплойта нет | Etherpad < 1.8.3 is affected by a denial of service in the import functionality.etherpad · etherpad | Высокая7,5 | — | 1,1 % | 28 апр. 2021 г. |
30Наблюдать | CVE-2020-22785Эксплойта нет | Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service.etherpad · etherpad · CWE-770 | Высокая7,5 | — | 1,1 % | 28 апр. 2021 г. |
30Наблюдать | CVE-2020-22784Эксплойта нет | In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database recordsetherpad · ueberdb · CWE-697 | Высокая7,5 | — | 1,0 % | 28 апр. 2021 г. |
29Наблюдать | CVE-2021-34816Эксплойта нет | An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by ietherpad · etherpad · CWE-88 | Высокая7,2 | — | 2,2 % | 21 июл. 2021 г. |
26Наблюдать | CVE-2020-22783Эксплойта нет | Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files.etherpad · etherpad · CWE-312 | Средняя6,5 | — | 0,6 % | 28 апр. 2021 г. |
24Наблюдать | CVE-2021-34817Эксплойта нет | A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML betherpad · etherpad · CWE-79 | Средняя6,1 | — | 1,3 % | 19 июл. 2021 г. |
24Наблюдать | CVE-2018-6834Эксплойта нет | static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.etherpad · etherpad lite · CWE-79 | Средняя6,1 | — | 0,9 % | 8 февр. 2018 г. |
24Наблюдать | CVE-2019-18209Эксплойта нет | templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Exploreretherpad · etherpad · CWE-79 | Средняя6,1 | — | 0,7 % | 18 окт. 2019 г. |
- CVE-2018-984543В плане
Etherpad Lite before 1.6.4 is exploitable for admin access.
КритическаяCVSS 9,8Proof of conceptEPSS 13 %etherpad · etherpad lite29 апр. 2018 г.
- CVE-2018-683540В плане
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access rest
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %etherpad · etherpad8 февр. 2018 г.
- CVE-2018-932640В плане
Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %etherpad · etherpad7 апр. 2018 г.
- CVE-2021-4380236Наблюдать
Admin privilege escalation and arbitrary code execution via malicious *.etherpad imports
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %etherpad · etherpad9 дек. 2021 г.
- CVE-2018-932732Наблюдать
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server.
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %etherpad · etherpad7 апр. 2018 г.
- CVE-2015-329731Наблюдать
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %etherpad · etherpad7 июл. 2017 г.
- CVE-2015-229831Наблюдать
node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an im
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %etherpad · etherpad12 янв. 2018 г.
- CVE-2015-408531Наблюдать
Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %etherpad · etherpad7 сент. 2017 г.
- CVE-2015-330931Наблюдать
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files wi
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %etherpad · etherpad13 февр. 2020 г.
- CVE-2018-932530Наблюдать
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %etherpad · etherpad7 апр. 2018 г.
- CVE-2020-2278130Наблюдать
In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %etherpad · etherpad28 апр. 2021 г.
- CVE-2020-2278230Наблюдать
Etherpad < 1.8.3 is affected by a denial of service in the import functionality.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %etherpad · etherpad28 апр. 2021 г.
- CVE-2020-2278530Наблюдать
Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %etherpad · etherpad28 апр. 2021 г.
- CVE-2020-2278430Наблюдать
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %etherpad · ueberdb28 апр. 2021 г.
- CVE-2021-3481629Наблюдать
An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by i
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %etherpad · etherpad21 июл. 2021 г.
- CVE-2020-2278326Наблюдать
Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %etherpad · etherpad28 апр. 2021 г.
- CVE-2021-3481724Наблюдать
A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML b
СредняяCVSS 6,1Эксплойта нетEPSS 1 %etherpad · etherpad19 июл. 2021 г.
- CVE-2018-683424Наблюдать
static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %etherpad · etherpad lite8 февр. 2018 г.
- CVE-2019-1820924Наблюдать
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer
СредняяCVSS 6,1Эксплойта нетEPSS 1 %etherpad · etherpad18 окт. 2019 г.