CVE-2013-0632
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-03-03Remediation due 2022-03-24
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.
9.8
CVSS
93.6%
EPSS (exploit prob.)
100th
EPSS percentile
2013-01-17
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-276
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | coldfusion | 9.0 |
| adobe | coldfusion | 9.0.1 |
| adobe | coldfusion | 9.0.2 |
| adobe | coldfusion | 10.0 |
Check a specific version with /api/v1/cve/match.
References
- http://www.adobe.com/support/security/advisories/apsa13-01.html
- http://www.adobe.com/support/security/bulletins/apsb13-03.html
- http://www.exploit-db.com/exploits/30210
- http://www.adobe.com/support/security/advisories/apsa13-01.html
- http://www.adobe.com/support/security/bulletins/apsb13-03.html
- http://www.exploit-db.com/exploits/30210
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0632
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-0632