4.3
CVSSv2

CVE-2014-2861

Published: 15/04/2014 Updated: 16/04/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Incomplete blacklist vulnerability in PaperThin CommonSpot prior to 7.0.2 and 8.x prior to 8.0.3 allows remote malicious users to conduct cross-site scripting (XSS) attacks via a crafted string, as demonstrated by bypassing a protection mechanism that removes only the "alert" string.

Vulnerable Product Search on Vulmon Subscribe to Product

paperthin commonspot content server

paperthin commonspot content server 8.0.2

paperthin commonspot content server 8.0.1

paperthin commonspot content server 8.0.0