01642 06 11 11 Arrange Call

Remote Code Execution via HTTP GET Request in PaperThin CommonSpot

CVE-2014-2868 · HIGH

CVE-2014-2868

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GET request to set a ColdFusion variable.

Learn more about our Web Application Penetration Testing UK.