Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Commonspot Content Server HIGH 10.0
CVE-2014-2863

Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecif…

Fix: after 7.0.1
Fix from $1,950 2014-04-15
Commonspot Content Server HIGH 10.0
CVE-2014-2864EPSS 5%

Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified …

Fix: after 7.0.1
Fix from $1,950 2014-04-15
Commonspot Content Server HIGH 10.0
CVE-2014-2866

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows remote attackers to per…

Fix: after 7.0.1
Fix from $1,950 2014-04-15
Commonspot Content Server HIGH 10.0
CVE-2014-2867

Unrestricted file upload vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code by…

Fix: after 7.0.1
Fix from $1,950 2014-04-15
Commonspot Content Server HIGH 10.0
CVE-2014-2874EPSS 5%

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via shell metacharacters in an unspecified c…

Fix: after 7.0.1
Fix from $1,950 2014-04-15
Commonspot Content Server HIGH 7.5
CVE-2014-2859

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request.

Fix: after 7.0.1
Fix from $1,950 2014-04-15
Commonspot Content Server HIGH 7.5
CVE-2014-2865

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a '\0' character, as demons…

Fix: after 7.0.1
Fix from $1,950 2014-04-15
Commonspot Content Server HIGH 7.5
CVE-2014-2868

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GE…

Fix: after 7.0.1
Fix from $1,950 2014-04-15
Commonspot Content Server MEDIUM 6.5
CVE-2014-2862

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticated user…

Fix: after 7.0.1
Fix from $1,600 2014-04-15
Commonspot Content Server MEDIUM 5.0
CVE-2014-2869

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified URIs, as d…

Fix: after 7.0.1
Fix from $1,600 2014-04-15
Commonspot Content Server MEDIUM 5.0
CVE-2014-2870

The default configuration of PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 uses cleartext for storage of credentials in a database, which ma…

Fix: after 7.0.1
Fix from $1,600 2014-04-15
Commonspot Content Server MEDIUM 5.0
CVE-2014-2871

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remote attacke…

Fix: after 7.0.1
Fix from $1,600 2014-04-15
Commonspot Content Server MEDIUM 5.0
CVE-2014-2872

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain potentially sensitive information from a directory listing v…

Fix: after 7.0.1
Fix from $1,600 2014-04-15
Commonspot Content Server MEDIUM 5.0
CVE-2014-2873

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not require authentication for access to log files, which allows remote attackers to obta…

Fix: after 7.0.1
Fix from $1,600 2014-04-15
Commonspot Content Server MEDIUM 5.0
CVE-2005-4575

PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter to loader.…

Fix: after 4.5
Fix from $1,600 2005-12-29