paperthin records
19 published records for vendor paperthin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 5.3%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-255 Credentials Management Errors1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2014-2864No exploit | Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspaperthin · commonspot content server · CWE-22 | Critical10.0 | — | 5.1% | Apr 15, 2014 |
42Plan | CVE-2014-2874No exploit | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via shell metacharacters in an unsppaperthin · commonspot content server · CWE-78 | Critical10.0 | — | 5.1% | Apr 15, 2014 |
41Plan | CVE-2014-2867No exploit | Unrestricted file upload vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrarpaperthin · commonspot content server | Critical10.0 | — | 4.9% | Apr 15, 2014 |
41Plan | CVE-2014-2863No exploit | Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have anpaperthin · commonspot content server · CWE-22 | Critical10.0 | — | 4.2% | Apr 15, 2014 |
41Plan | CVE-2014-2866No exploit | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows remote attackepaperthin · commonspot content server · CWE-94 | Critical10.0 | — | 3.4% | Apr 15, 2014 |
31Monitor | CVE-2014-2868No exploit | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using apaperthin · commonspot content server | High7.5 | — | 3.3% | Apr 15, 2014 |
31Monitor | CVE-2014-2865No exploit | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a '\0' character, paperthin · commonspot content server · CWE-264 | High7.5 | — | 2.4% | Apr 15, 2014 |
31Monitor | CVE-2014-2859No exploit | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request.paperthin · commonspot content server · CWE-264 | High7.5 | — | 2.4% | Apr 15, 2014 |
27Monitor | CVE-2014-2862No exploit | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticpaperthin · commonspot content server · CWE-264 | Medium6.5 | — | 1.8% | Apr 15, 2014 |
21Monitor | CVE-2014-2873No exploit | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not require authentication for access to log files, which allows remote attackerpaperthin · commonspot content server · CWE-200 | Medium5.0 | — | 2.1% | Apr 15, 2014 |
21Monitor | CVE-2014-2869No exploit | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified Upaperthin · commonspot content server · CWE-200 | Medium5.0 | — | 2.0% | Apr 15, 2014 |
21Monitor | CVE-2014-2872No exploit | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain potentially sensitive information from a directory paperthin · commonspot content server · CWE-200 | Medium5.0 | — | 2.0% | Apr 15, 2014 |
21Monitor | CVE-2014-2871No exploit | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remotpaperthin · commonspot content server · CWE-200 | Medium5.0 | — | 2.0% | Apr 15, 2014 |
20Monitor | CVE-2014-2870No exploit | The default configuration of PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 uses cleartext for storage of credentials in a database,paperthin · commonspot content server · CWE-255 | Medium5.0 | — | 1.5% | Apr 15, 2014 |
20Monitor | CVE-2005-4575No exploit | PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter tpaperthin · commonspot content server | Medium5.0 | — | 1.4% | Dec 29, 2005 |
18Monitor | CVE-2014-2861No exploit | Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site spaperthin · commonspot content server | Medium4.3 | — | 2.2% | Apr 15, 2014 |
18Monitor | CVE-2014-2860No exploit | Multiple cross-site scripting (XSS) vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to injepaperthin · commonspot content server · CWE-79 | Medium4.3 | — | 2.0% | Apr 15, 2014 |
18Monitor | CVE-2005-4574Proof of concept | Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to injpaperthin · commonspot content server | Medium4.3 | — | 1.7% | Dec 29, 2005 |
17Monitor | CVE-2010-0468Proof of concept | Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject paperthin · commonspot content server · CWE-79 | Medium4.3 | — | 1.5% | Feb 2, 2010 |
- CVE-2014-286442Plan
Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an uns
CriticalCVSS 10.0No exploitEPSS 5%paperthin · commonspot content serverApr 15, 2014
- CVE-2014-287442Plan
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via shell metacharacters in an unsp
CriticalCVSS 10.0No exploitEPSS 5%paperthin · commonspot content serverApr 15, 2014
- CVE-2014-286741Plan
Unrestricted file upload vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrar
CriticalCVSS 10.0No exploitEPSS 5%paperthin · commonspot content serverApr 15, 2014
- CVE-2014-286341Plan
Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an
CriticalCVSS 10.0No exploitEPSS 4%paperthin · commonspot content serverApr 15, 2014
- CVE-2014-286641Plan
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows remote attacke
CriticalCVSS 10.0No exploitEPSS 3%paperthin · commonspot content serverApr 15, 2014
- CVE-2014-286831Monitor
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using a
HighCVSS 7.5No exploitEPSS 3%paperthin · commonspot content serverApr 15, 2014
- CVE-2014-286531Monitor
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a '\0' character,
HighCVSS 7.5No exploitEPSS 2%paperthin · commonspot content serverApr 15, 2014
- CVE-2014-285931Monitor
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request.
HighCVSS 7.5No exploitEPSS 2%paperthin · commonspot content serverApr 15, 2014
- CVE-2014-286227Monitor
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authentic
MediumCVSS 6.5No exploitEPSS 2%paperthin · commonspot content serverApr 15, 2014
- CVE-2014-287321Monitor
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not require authentication for access to log files, which allows remote attacker
MediumCVSS 5.0No exploitEPSS 2%paperthin · commonspot content serverApr 15, 2014
- CVE-2014-286921Monitor
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified U
MediumCVSS 5.0No exploitEPSS 2%paperthin · commonspot content serverApr 15, 2014
- CVE-2014-287221Monitor
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain potentially sensitive information from a directory
MediumCVSS 5.0No exploitEPSS 2%paperthin · commonspot content serverApr 15, 2014
- CVE-2014-287121Monitor
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remot
MediumCVSS 5.0No exploitEPSS 2%paperthin · commonspot content serverApr 15, 2014
- CVE-2014-287020Monitor
The default configuration of PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 uses cleartext for storage of credentials in a database,
MediumCVSS 5.0No exploitEPSS 1%paperthin · commonspot content serverApr 15, 2014
- CVE-2005-457520Monitor
PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter t
MediumCVSS 5.0No exploitEPSS 1%paperthin · commonspot content serverDec 29, 2005
- CVE-2014-286118Monitor
Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site s
MediumCVSS 4.3No exploitEPSS 2%paperthin · commonspot content serverApr 15, 2014
- CVE-2014-286018Monitor
Multiple cross-site scripting (XSS) vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to inje
MediumCVSS 4.3No exploitEPSS 2%paperthin · commonspot content serverApr 15, 2014
- CVE-2005-457418Monitor
Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inj
MediumCVSS 4.3Proof of conceptEPSS 2%paperthin · commonspot content serverDec 29, 2005
- CVE-2010-046817Monitor
Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject
MediumCVSS 4.3Proof of conceptEPSS 2%paperthin · commonspot content serverFeb 2, 2010