Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the bNewWindow parameter.
- http://pridels0.blogspot.com/2005/12/commonspot-content-server-vuln.html
No PoCs found on GitHub currently.