etherpad kayıtları
etherpad üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %10,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-790 Improper Filtering of Special Elements1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2018-9845Kavram kanıtı | Etherpad Lite before 1.6.4 is exploitable for admin access.etherpad · etherpad lite · CWE-178 | Kritik9,8 | — | %12,9 | 29 Nis 2018 |
40Planlayın | CVE-2018-6835İstismar yok | node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restetherpad · etherpad · CWE-20 | Kritik9,8 | — | %2,3 | 8 Şub 2018 |
40Planlayın | CVE-2018-9326İstismar yok | Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.etherpad · etherpad | Kritik9,8 | — | %2,0 | 7 Nis 2018 |
36İzleyin | CVE-2021-43802İstismar yok | Admin privilege escalation and arbitrary code execution via malicious *.etherpad importsetherpad · etherpad · CWE-790 | Yüksek8,8 | — | %2,0 | 9 Ara 2021 |
32İzleyin | CVE-2018-9327İstismar yok | Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server.etherpad · etherpad · CWE-20 | Yüksek8,1 | — | %1,6 | 7 Nis 2018 |
31İzleyin | CVE-2015-3297İstismar yok | Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files byetherpad · etherpad · CWE-22 | Yüksek7,5 | — | %5,0 | 7 Tem 2017 |
31İzleyin | CVE-2015-2298İstismar yok | node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an imetherpad · etherpad · CWE-200 | Yüksek7,5 | — | %2,3 | 12 Oca 2018 |
31İzleyin | CVE-2015-4085İstismar yok | Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.etherpad · etherpad · CWE-22 | Yüksek7,5 | — | %2,3 | 7 Eyl 2017 |
31İzleyin | CVE-2015-3309İstismar yok | Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files wietherpad · etherpad · CWE-22 | Yüksek7,5 | — | %2,3 | 13 Şub 2020 |
30İzleyin | CVE-2018-9325İstismar yok | Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.etherpad · etherpad · CWE-200 | Yüksek7,5 | — | %1,2 | 7 Nis 2018 |
30İzleyin | CVE-2020-22781İstismar yok | In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash etherpad · etherpad · CWE-89 | Yüksek7,5 | — | %1,1 | 28 Nis 2021 |
30İzleyin | CVE-2020-22782İstismar yok | Etherpad < 1.8.3 is affected by a denial of service in the import functionality.etherpad · etherpad | Yüksek7,5 | — | %1,1 | 28 Nis 2021 |
30İzleyin | CVE-2020-22785İstismar yok | Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service.etherpad · etherpad · CWE-770 | Yüksek7,5 | — | %1,1 | 28 Nis 2021 |
30İzleyin | CVE-2020-22784İstismar yok | In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database recordsetherpad · ueberdb · CWE-697 | Yüksek7,5 | — | %1,0 | 28 Nis 2021 |
29İzleyin | CVE-2021-34816İstismar yok | An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by ietherpad · etherpad · CWE-88 | Yüksek7,2 | — | %2,2 | 21 Tem 2021 |
26İzleyin | CVE-2020-22783İstismar yok | Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files.etherpad · etherpad · CWE-312 | Orta6,5 | — | %0,6 | 28 Nis 2021 |
24İzleyin | CVE-2021-34817İstismar yok | A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML betherpad · etherpad · CWE-79 | Orta6,1 | — | %1,3 | 19 Tem 2021 |
24İzleyin | CVE-2018-6834İstismar yok | static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.etherpad · etherpad lite · CWE-79 | Orta6,1 | — | %0,9 | 8 Şub 2018 |
24İzleyin | CVE-2019-18209İstismar yok | templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Exploreretherpad · etherpad · CWE-79 | Orta6,1 | — | %0,7 | 18 Eki 2019 |
- CVE-2018-984543Planlayın
Etherpad Lite before 1.6.4 is exploitable for admin access.
KritikCVSS 9,8Kavram kanıtıEPSS %13etherpad · etherpad lite29 Nis 2018
- CVE-2018-683540Planlayın
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access rest
KritikCVSS 9,8İstismar yokEPSS %2etherpad · etherpad8 Şub 2018
- CVE-2018-932640Planlayın
Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.
KritikCVSS 9,8İstismar yokEPSS %2etherpad · etherpad7 Nis 2018
- CVE-2021-4380236İzleyin
Admin privilege escalation and arbitrary code execution via malicious *.etherpad imports
YüksekCVSS 8,8İstismar yokEPSS %2etherpad · etherpad9 Ara 2021
- CVE-2018-932732İzleyin
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server.
YüksekCVSS 8,1İstismar yokEPSS %2etherpad · etherpad7 Nis 2018
- CVE-2015-329731İzleyin
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by
YüksekCVSS 7,5İstismar yokEPSS %5etherpad · etherpad7 Tem 2017
- CVE-2015-229831İzleyin
node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an im
YüksekCVSS 7,5İstismar yokEPSS %2etherpad · etherpad12 Oca 2018
- CVE-2015-408531İzleyin
Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.
YüksekCVSS 7,5İstismar yokEPSS %2etherpad · etherpad7 Eyl 2017
- CVE-2015-330931İzleyin
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files wi
YüksekCVSS 7,5İstismar yokEPSS %2etherpad · etherpad13 Şub 2020
- CVE-2018-932530İzleyin
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.
YüksekCVSS 7,5İstismar yokEPSS %1etherpad · etherpad7 Nis 2018
- CVE-2020-2278130İzleyin
In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash
YüksekCVSS 7,5İstismar yokEPSS %1etherpad · etherpad28 Nis 2021
- CVE-2020-2278230İzleyin
Etherpad < 1.8.3 is affected by a denial of service in the import functionality.
YüksekCVSS 7,5İstismar yokEPSS %1etherpad · etherpad28 Nis 2021
- CVE-2020-2278530İzleyin
Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service.
YüksekCVSS 7,5İstismar yokEPSS %1etherpad · etherpad28 Nis 2021
- CVE-2020-2278430İzleyin
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records
YüksekCVSS 7,5İstismar yokEPSS %1etherpad · ueberdb28 Nis 2021
- CVE-2021-3481629İzleyin
An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by i
YüksekCVSS 7,2İstismar yokEPSS %2etherpad · etherpad21 Tem 2021
- CVE-2020-2278326İzleyin
Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files.
OrtaCVSS 6,5İstismar yokEPSS %1etherpad · etherpad28 Nis 2021
- CVE-2021-3481724İzleyin
A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML b
OrtaCVSS 6,1İstismar yokEPSS %1etherpad · etherpad19 Tem 2021
- CVE-2018-683424İzleyin
static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.
OrtaCVSS 6,1İstismar yokEPSS %1etherpad · etherpad lite8 Şub 2018
- CVE-2019-1820924İzleyin
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer
OrtaCVSS 6,1İstismar yokEPSS %1etherpad · etherpad18 Eki 2019