Security Advisory
CVE-2014-2868
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GET request to set a ColdFusion variable.