CVE Vulnerabilities

CVE-2014-2868

Published: Apr 15, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GET request to set a ColdFusion variable.

Affected Software

NameVendorStart VersionEnd Version
Commonspot_content_serverPaperthin*7.0.1 (including)
Commonspot_content_serverPaperthin8.0.0 (including)8.0.0 (including)
Commonspot_content_serverPaperthin8.0.1 (including)8.0.1 (including)
Commonspot_content_serverPaperthin8.0.2 (including)8.0.2 (including)

References