Vulnerabilities
Vulnerable Software
Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the bNewWindow parameter.
CVSS Score
4.3
EPSS Score
0.038
Published
2005-12-29
PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter to loader.cfm with a url parameter set to email-login-info.cfm, which leaks the full pathname in the resulting error message.
CVSS Score
5.0
EPSS Score
0.004
Published
2005-12-29


Contact Us

Shodan ® - All rights reserved