Paperthin

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 19
    Known Exploited: 0
    5
    Critical Level Threats
    3
    High Level Threats
    11
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2014-2872

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain potentially sensitive information from a directory listing via unspecified vectors.

    Last Modified: Apr 12, 2025
    Published: Apr 15, 2014

    CVE-2014-2861

    Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string, as demonstrated by bypassing a protection mechanism that removes only the "alert" string.

    Last Modified: Apr 12, 2025
    Published: Apr 15, 2014

    CVE-2014-2859

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request.

    Last Modified: Apr 12, 2025
    Published: Apr 15, 2014

    CVE-2014-2860

    Multiple cross-site scripting (XSS) vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to inject arbitrary web script or HTML via a crafted HTTP request to a (1) ColdFusion or (2) JavaScript component.

    Last Modified: Apr 12, 2025
    Published: Apr 15, 2014

    CVE-2014-2862

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticated users to perform actions via unknown vectors.

    Last Modified: Apr 12, 2025
    Published: Apr 15, 2014
    Items Per Page