İçeriğe atla
Noroxi

etherpad kayıtları

etherpad üreticisine ait 19 yayımlanmış kayıt.

Tüm kayıtlar

19 kayıt
  • CVE-2018-9845
    43Planlayın

    Etherpad Lite before 1.6.4 is exploitable for admin access.

    KritikCVSS 9,8Kavram kanıtıEPSS %13

    etherpad · etherpad lite29 Nis 2018

  • CVE-2018-6835
    40Planlayın

    node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access rest

    KritikCVSS 9,8İstismar yokEPSS %2

    etherpad · etherpad8 Şub 2018

  • CVE-2018-9326
    40Planlayın

    Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.

    KritikCVSS 9,8İstismar yokEPSS %2

    etherpad · etherpad7 Nis 2018

  • CVE-2021-43802
    36İzleyin

    Admin privilege escalation and arbitrary code execution via malicious *.etherpad imports

    YüksekCVSS 8,8İstismar yokEPSS %2

    etherpad · etherpad9 Ara 2021

  • CVE-2018-9327
    32İzleyin

    Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server.

    YüksekCVSS 8,1İstismar yokEPSS %2

    etherpad · etherpad7 Nis 2018

  • CVE-2015-3297
    31İzleyin

    Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by

    YüksekCVSS 7,5İstismar yokEPSS %5

    etherpad · etherpad7 Tem 2017

  • CVE-2015-2298
    31İzleyin

    node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an im

    YüksekCVSS 7,5İstismar yokEPSS %2

    etherpad · etherpad12 Oca 2018

  • CVE-2015-4085
    31İzleyin

    Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.

    YüksekCVSS 7,5İstismar yokEPSS %2

    etherpad · etherpad7 Eyl 2017

  • CVE-2015-3309
    31İzleyin

    Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files wi

    YüksekCVSS 7,5İstismar yokEPSS %2

    etherpad · etherpad13 Şub 2020

  • CVE-2018-9325
    30İzleyin

    Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.

    YüksekCVSS 7,5İstismar yokEPSS %1

    etherpad · etherpad7 Nis 2018

  • CVE-2020-22781
    30İzleyin

    In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash

    YüksekCVSS 7,5İstismar yokEPSS %1

    etherpad · etherpad28 Nis 2021

  • CVE-2020-22782
    30İzleyin

    Etherpad < 1.8.3 is affected by a denial of service in the import functionality.

    YüksekCVSS 7,5İstismar yokEPSS %1

    etherpad · etherpad28 Nis 2021

  • CVE-2020-22785
    30İzleyin

    Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service.

    YüksekCVSS 7,5İstismar yokEPSS %1

    etherpad · etherpad28 Nis 2021

  • CVE-2020-22784
    30İzleyin

    In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records

    YüksekCVSS 7,5İstismar yokEPSS %1

    etherpad · ueberdb28 Nis 2021

  • CVE-2021-34816
    29İzleyin

    An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by i

    YüksekCVSS 7,2İstismar yokEPSS %2

    etherpad · etherpad21 Tem 2021

  • CVE-2020-22783
    26İzleyin

    Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files.

    OrtaCVSS 6,5İstismar yokEPSS %1

    etherpad · etherpad28 Nis 2021

  • CVE-2021-34817
    24İzleyin

    A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML b

    OrtaCVSS 6,1İstismar yokEPSS %1

    etherpad · etherpad19 Tem 2021

  • CVE-2018-6834
    24İzleyin

    static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.

    OrtaCVSS 6,1İstismar yokEPSS %1

    etherpad · etherpad lite8 Şub 2018

  • CVE-2019-18209
    24İzleyin

    templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer

    OrtaCVSS 6,1İstismar yokEPSS %1

    etherpad · etherpad18 Eki 2019