Paperthin / Commonspot Content Server
19 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2014-2874 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via shell metacharacters in an unspecified context. | HIGH | 10.0 | Apr 15, 2014 |
| CVE-2014-2873 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not require authentication for access to log files, which allows remote attackers to obtain sensiti… | MEDIUM | 5.0 | Apr 15, 2014 |
| CVE-2014-2872 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain potentially sensitive information from a directory listing via unspeci… | MEDIUM | 5.0 | Apr 15, 2014 |
| CVE-2014-2871 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remote attackers to obta… | MEDIUM | 5.0 | Apr 15, 2014 |
| CVE-2014-2870 | The default configuration of PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 uses cleartext for storage of credentials in a database, which makes it eas… | MEDIUM | 5.0 | Apr 15, 2014 |
| CVE-2014-2869 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified URIs, as demonstrate… | MEDIUM | 5.0 | Apr 15, 2014 |
| CVE-2014-2868 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GET request… | HIGH | 7.5 | Apr 15, 2014 |
| CVE-2014-2867 | Unrestricted file upload vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code by uploading… | HIGH | 10.0 | Apr 15, 2014 |
| CVE-2014-2866 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows remote attackers to perform unspe… | HIGH | 10.0 | Apr 15, 2014 |
| CVE-2014-2865 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a '\0' character, as demonstrated by… | HIGH | 7.5 | Apr 15, 2014 |
| CVE-2014-2864 | Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via… | HIGH | 10.0 | Apr 15, 2014 |
| CVE-2014-2863 | Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact… | HIGH | 10.0 | Apr 15, 2014 |
| CVE-2014-2862 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticated users to perfo… | MEDIUM | 6.5 | Apr 15, 2014 |
| CVE-2014-2861 | Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site scripting (XSS) atta… | MEDIUM | 4.3 | Apr 15, 2014 |
| CVE-2014-2860 | Multiple cross-site scripting (XSS) vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to inject arbitrary web sc… | MEDIUM | 4.3 | Apr 15, 2014 |
| CVE-2014-2859 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request. | HIGH | 7.5 | Apr 15, 2014 |
| CVE-2010-0468 | Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject arbitrary web scrip… | MEDIUM | 4.3 | Feb 2, 2010 |
| CVE-2005-4575 | PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter to loader.cfm with a… | MEDIUM | 5.0 | Dec 29, 2005 |
| CVE-2005-4574 | Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web s… | MEDIUM | 4.3 | Dec 29, 2005 |
Showing 1 to 19 of 19 CVEs