CVE-2014-2868

Publication date

2014-04-15 23:00:00

Family

mitre

State

PUBLISHED

Description

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GET request to set a ColdFusion variable.