Lucene search

K
cveMitreCVE-2014-2861
HistoryApr 15, 2014 - 11:13 p.m.

CVE-2014-2861

2014-04-1523:13:17
mitre
web.nvd.nist.gov
26
vulnerability
paperthin commonspot
xss
cross-site scripting
nvd
cve-2014-2861

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.004

Percentile

75.1%

Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string, as demonstrated by bypassing a protection mechanism that removes only the “alert” string.

Affected configurations

Nvd
Node
paperthincommonspot_content_serverRange7.0.1
OR
paperthincommonspot_content_serverMatch8.0.0
OR
paperthincommonspot_content_serverMatch8.0.1
OR
paperthincommonspot_content_serverMatch8.0.2
VendorProductVersionCPE
paperthincommonspot_content_server*cpe:2.3:a:paperthin:commonspot_content_server:*:*:*:*:*:*:*:*
paperthincommonspot_content_server8.0.0cpe:2.3:a:paperthin:commonspot_content_server:8.0.0:*:*:*:*:*:*:*
paperthincommonspot_content_server8.0.1cpe:2.3:a:paperthin:commonspot_content_server:8.0.1:*:*:*:*:*:*:*
paperthincommonspot_content_server8.0.2cpe:2.3:a:paperthin:commonspot_content_server:8.0.2:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.004

Percentile

75.1%

Related for CVE-2014-2861