Skip to content

CVE-2014-2868

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GET request to set a ColdFusion variable.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0134 (1.3%)
Percentile: 80.1%
EPSS: 2026-05-06

Affects

paperthin:commonspot_content_server

Technical description

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GET request to set a ColdFusion variable.

Published: 4/15/2014, 11:13:17 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam