« Volver al listado

CVE-2014-2861

Estado: ModificadaMedia (4.3)—

Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string, as demonstrated by bypassing a protection mechanism that removes only the "alert" string.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-2861",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-04-15T23:13:17.353",
  "references": [
    {
      "url": "http://www.kb.cert.org/vuls/id/437385",
      "tags": [
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/437385",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string, as demonstrated by bypassing a protection mechanism that removes only the \"alert\" string."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de lista negra incompleta en PaperThin CommonSpot anterior a 7.0.2 y 8.x anterior a 8.0.3 permite a atacantes remotos realizar ataques de XSS a través de una cadena manipulada, tal y como fue demostrado evadiendo un mecanismo que elimina solamente la cadena \"alert\"."
    }
  ],
  "lastModified": "2026-06-17T00:07:16.553",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:paperthin:commonspot_content_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD08E3EF-D249-4A29-A3E7-21BEA641CD84",
              "versionEndIncluding": "7.0.1"
            },
            {
              "criteria": "cpe:2.3:a:paperthin:commonspot_content_server:8.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0FE207C4-6F10-49EA-9FEF-AD567BDB59C6"
            },
            {
              "criteria": "cpe:2.3:a:paperthin:commonspot_content_server:8.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4602A36E-5F5B-4DC9-B556-097F0847F30B"
            },
            {
              "criteria": "cpe:2.3:a:paperthin:commonspot_content_server:8.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6EDBF14-8C62-4E0F-A7A4-E196A9C21EA4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Per: https://cwe.mitre.org/data/definitions/184.html \"CWE-184: Incomplete Blacklist\"",
  "sourceIdentifier": "cve@mitre.org"
}