Skip to content
Noroxi

paperthin records

19 published records for vendor paperthin.

All records

19 records
  • Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an uns

    CriticalCVSS 10.0No exploitEPSS 5%

    paperthin · commonspot content serverApr 15, 2014

  • PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via shell metacharacters in an unsp

    CriticalCVSS 10.0No exploitEPSS 5%

    paperthin · commonspot content serverApr 15, 2014

  • Unrestricted file upload vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrar

    CriticalCVSS 10.0No exploitEPSS 5%

    paperthin · commonspot content serverApr 15, 2014

  • Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an

    CriticalCVSS 10.0No exploitEPSS 4%

    paperthin · commonspot content serverApr 15, 2014

  • PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows remote attacke

    CriticalCVSS 10.0No exploitEPSS 3%

    paperthin · commonspot content serverApr 15, 2014

  • CVE-2014-2868
    31Monitor

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using a

    HighCVSS 7.5No exploitEPSS 3%

    paperthin · commonspot content serverApr 15, 2014

  • CVE-2014-2865
    31Monitor

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a '\0' character,

    HighCVSS 7.5No exploitEPSS 2%

    paperthin · commonspot content serverApr 15, 2014

  • CVE-2014-2859
    31Monitor

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request.

    HighCVSS 7.5No exploitEPSS 2%

    paperthin · commonspot content serverApr 15, 2014

  • CVE-2014-2862
    27Monitor

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authentic

    MediumCVSS 6.5No exploitEPSS 2%

    paperthin · commonspot content serverApr 15, 2014

  • CVE-2014-2873
    21Monitor

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not require authentication for access to log files, which allows remote attacker

    MediumCVSS 5.0No exploitEPSS 2%

    paperthin · commonspot content serverApr 15, 2014

  • CVE-2014-2869
    21Monitor

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified U

    MediumCVSS 5.0No exploitEPSS 2%

    paperthin · commonspot content serverApr 15, 2014

  • CVE-2014-2872
    21Monitor

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain potentially sensitive information from a directory

    MediumCVSS 5.0No exploitEPSS 2%

    paperthin · commonspot content serverApr 15, 2014

  • CVE-2014-2871
    21Monitor

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remot

    MediumCVSS 5.0No exploitEPSS 2%

    paperthin · commonspot content serverApr 15, 2014

  • CVE-2014-2870
    20Monitor

    The default configuration of PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 uses cleartext for storage of credentials in a database,

    MediumCVSS 5.0No exploitEPSS 1%

    paperthin · commonspot content serverApr 15, 2014

  • CVE-2005-4575
    20Monitor

    PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter t

    MediumCVSS 5.0No exploitEPSS 1%

    paperthin · commonspot content serverDec 29, 2005

  • CVE-2014-2861
    18Monitor

    Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site s

    MediumCVSS 4.3No exploitEPSS 2%

    paperthin · commonspot content serverApr 15, 2014

  • CVE-2014-2860
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to inje

    MediumCVSS 4.3No exploitEPSS 2%

    paperthin · commonspot content serverApr 15, 2014

  • CVE-2005-4574
    18Monitor

    Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inj

    MediumCVSS 4.3Proof of conceptEPSS 2%

    paperthin · commonspot content serverDec 29, 2005

  • CVE-2010-0468
    17Monitor

    Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject

    MediumCVSS 4.3Proof of conceptEPSS 2%

    paperthin · commonspot content serverFeb 2, 2010