Back to search
CVE-2015-3297
Published: Jul 7, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20150410 Re: CVE Request for read-only directory traversal in Etherpad Minify
mailing-list
x_refsource_MLIST
74056
vdb-entry
x_refsource_BID
https://github.com/ether/etherpad-lite/commit/9d4e5f6
x_refsource_CONFIRM
[oss-security] 20150412 Corrections to CVE-2015-3297
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now