Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown

CVE-2018-9845

Disclosure Date: April 29, 2018 (last updated November 26, 2024)
Etherpad Lite before 1.6.4 is exploitable for admin access.
0
Attacker Value
Unknown

CVE-2018-9325

Disclosure Date: April 07, 2018 (last updated November 26, 2024)
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.
0
Attacker Value
Unknown

CVE-2018-9327

Disclosure Date: April 07, 2018 (last updated November 26, 2024)
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be configured to use a document database (DirtyDB, CouchDB, MongoDB, or RethinkDB).
0
Attacker Value
Unknown

CVE-2018-9326

Disclosure Date: April 07, 2018 (last updated November 26, 2024)
Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2018-6835

Disclosure Date: February 08, 2018 (last updated November 26, 2024)
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.
0
Attacker Value
Unknown

CVE-2018-6834

Disclosure Date: February 08, 2018 (last updated November 26, 2024)
static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.
0
Attacker Value
Unknown

CVE-2015-2298

Disclosure Date: January 12, 2018 (last updated November 26, 2024)
node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an improper substring check when exporting a padID.
0
Attacker Value
Unknown

CVE-2015-4085

Disclosure Date: September 07, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.
0
Attacker Value
Unknown

CVE-2015-3297

Disclosure Date: July 07, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests.
0