Перейти к содержимому
Noroxi

Записи paperthin

19 опубликованных записей вендора paperthin.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
3
С записью об исправлении
5,3 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

19 записей
  • CVE-2014-2864
    42В плане

    Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an uns

    КритическаяCVSS 10,0Эксплойта нетEPSS 5 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2014-2874
    42В плане

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via shell metacharacters in an unsp

    КритическаяCVSS 10,0Эксплойта нетEPSS 5 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2014-2867
    41В плане

    Unrestricted file upload vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrar

    КритическаяCVSS 10,0Эксплойта нетEPSS 5 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2014-2863
    41В плане

    Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an

    КритическаяCVSS 10,0Эксплойта нетEPSS 4 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2014-2866
    41В плане

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows remote attacke

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2014-2868
    31Наблюдать

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using a

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2014-2865
    31Наблюдать

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a '\0' character,

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2014-2859
    31Наблюдать

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2014-2862
    27Наблюдать

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authentic

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2014-2873
    21Наблюдать

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not require authentication for access to log files, which allows remote attacker

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2014-2869
    21Наблюдать

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified U

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2014-2872
    21Наблюдать

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain potentially sensitive information from a directory

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2014-2871
    21Наблюдать

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remot

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2014-2870
    20Наблюдать

    The default configuration of PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 uses cleartext for storage of credentials in a database,

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2005-4575
    20Наблюдать

    PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter t

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    paperthin · commonspot content server29 дек. 2005 г.

  • CVE-2014-2861
    18Наблюдать

    Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site s

    СредняяCVSS 4,3Эксплойта нетEPSS 2 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2014-2860
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to inje

    СредняяCVSS 4,3Эксплойта нетEPSS 2 %

    paperthin · commonspot content server15 апр. 2014 г.

  • CVE-2005-4574
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inj

    СредняяCVSS 4,3Proof of conceptEPSS 2 %

    paperthin · commonspot content server29 дек. 2005 г.

  • CVE-2010-0468
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject

    СредняяCVSS 4,3Proof of conceptEPSS 2 %

    paperthin · commonspot content server2 февр. 2010 г.