Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2018-9845
Disclosure Date: April 29, 2018 (last updated November 26, 2024)
Etherpad Lite before 1.6.4 is exploitable for admin access.
0
Attacker Value
Unknown
CVE-2018-9325
Disclosure Date: April 07, 2018 (last updated November 26, 2024)
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.
0
Attacker Value
Unknown
CVE-2018-9327
Disclosure Date: April 07, 2018 (last updated November 26, 2024)
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be configured to use a document database (DirtyDB, CouchDB, MongoDB, or RethinkDB).
0
Attacker Value
Unknown
CVE-2018-9326
Disclosure Date: April 07, 2018 (last updated November 26, 2024)
Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2018-6835
Disclosure Date: February 08, 2018 (last updated November 26, 2024)
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.
0
Attacker Value
Unknown
CVE-2018-6834
Disclosure Date: February 08, 2018 (last updated November 26, 2024)
static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.
0
Attacker Value
Unknown
CVE-2015-2298
Disclosure Date: January 12, 2018 (last updated November 26, 2024)
node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an improper substring check when exporting a padID.
0
Attacker Value
Unknown
CVE-2015-4085
Disclosure Date: September 07, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.
0
Attacker Value
Unknown
CVE-2015-3297
Disclosure Date: July 07, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests.
0