Lucene search

K
cve[email protected]CVE-2014-2867
HistoryOct 03, 2022 - 4:20 p.m.

CVE-2014-2867

2022-10-0316:20:48
web.nvd.nist.gov
24
cve-2014-2867
unrestricted file upload
paperthin commonspot
remote code execution
coldfusion page
security vulnerability

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

82.3%

Unrestricted file upload vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code by uploading a ColdFusion page, and then accessing it via unspecified vectors.

Affected configurations

NVD
Node
paperthincommonspot_content_serverRange7.0.1
OR
paperthincommonspot_content_serverMatch8.0.0
OR
paperthincommonspot_content_serverMatch8.0.1
OR
paperthincommonspot_content_serverMatch8.0.2

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

82.3%

Related for CVE-2014-2867