← Back

CVE-2013-0632

nvd nist
Published: Jan 17, 2013Modified: Apr 21, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.

Affected (4)

Products: Adobe: Coldfusion
1 product
Coldfusion
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 10.0
Version 9.0.1
Version 9.0.2
Version 9.0

References (7)

Source: psirt@adobe.com
MitigationVendor Advisory
Source: psirt@adobe.com
Broken LinkVendor Advisory
Source: psirt@adobe.com
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.