Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter to loader.cfm with a url parameter set to email-login-info.cfm, which leaks the full pathname in the resulting error message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PaperThin CommonSpot Content Server敏感信息泄露漏洞
Vulnerability Description
PaperThin CommonSpot Content Server 4.5及更早版本使得远程攻击者可通过一个传到loader.cfm的无效errmsg参数和一个email-login-info.cfm中设置的url参数,造成错误信息中泄露完整路径,获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A