Skip to main content

Vendor/product archive

paperthin / commonspot_content_server CVEs

Beta · best-effort

19 CVEs tagged to paperthin / commonspot_content_server5 Critical, 3 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2014-2874

Published Apr 15, 2014

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via shell metacharacters in an unspecified context.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-2873

Published Apr 15, 2014

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not require authentication for access to log files, which allows remote attackers to obtain sensitive server informatio…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2872

Published Apr 15, 2014

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain potentially sensitive information from a directory listing via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2871

Published Apr 15, 2014

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remote attackers to obtain sensitive informa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2870

Published Apr 15, 2014

The default configuration of PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 uses cleartext for storage of credentials in a database, which makes it easier for context-depe…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2869

Published Apr 15, 2014

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified URIs, as demonstrated by pathname, SQL s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2868

Published Apr 15, 2014

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GET request to set a ColdFusion…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2867

Published Apr 15, 2014

Unrestricted file upload vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code by uploading a ColdFusion page,…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-2866

Published Apr 15, 2014

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows remote attackers to perform unspecified operations by…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-2865

Published Apr 15, 2014

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a '\0' character, as demonstrated by using this character…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2864

Published Apr 15, 2014

Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a filename paramete…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-2863

Published Apr 15, 2014

Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a full pathname…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-2862

Published Apr 15, 2014

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticated users to perform actions via unkno…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2861

Published Apr 15, 2014

Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted st…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2860

Published Apr 15, 2014

Multiple cross-site scripting (XSS) vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to inject arbitrary web script or HTML via a c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0468

Published Feb 2, 2010

Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject arbitrary web script or HTML via the ur…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4574

Published Dec 29, 2005

Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4575

Published Dec 29, 2005

PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter to loader.cfm with a url parameter set t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1