Etherpad Lite是Etherpad基金会的一套开源的富文本在线协作软件。 Etherpad Lite 1.6.4之前版本中的webaccess.js文件存在安全漏洞。远程攻击者可通过发送特制的请求利用该漏洞绕过安全限制,获取系统的管理权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Etherpad Lite before 1.6.4 is exploitable for admin access. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-9845.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-10545 | PHP 安全漏洞 | |
| CVE-2018-10546 | PHP 安全漏洞 | |
| CVE-2018-10547 | PHP 输入验证漏洞 | |
| CVE-2018-10548 | PHP 安全漏洞 | |
| CVE-2018-10549 | PHP 安全漏洞 | |
| CVE-2018-10534 | GNU Binutils Binary File Descriptor库安全漏洞 | |
| CVE-2018-10535 | GNU Binutils Binary File Descriptor库安全漏洞 | |
| CVE-2018-10536 | WavPack 安全漏洞 | |
| CVE-2018-10537 | WavPack W64解析器组件安全漏洞 | |
| CVE-2018-10538 | WavPack 安全漏洞 | |
| CVE-2018-10539 | WavPack 安全漏洞 | |
| CVE-2018-10540 | WavPack 安全漏洞 | |
| CVE-2018-10528 | LibRaw 缓冲区错误漏洞 | |
| CVE-2018-10529 | LibRaw 安全漏洞 |
No comments yet