CVE-2013-0632
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.
- Affected products
- Coldfusion
- Adobe Coldfusion
- = 9.0, 9.0.1, 9.0.2, 10.0
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 93.7% (100th percentile)
- Weakness
- CWE-276
- NVD status
- Analyzed
- Published
- 2013-01-17
CVE-2013-0632 at NVD
13 known exploits for CVE-2013-0632
Proof-of-concept code and exploit modules indexed by Sploitus
clusterd - Application Server Attack Toolkit
Adobe ColdFusion 9 Administrative Login Bypass
Adobe ColdFusion APSB13-03 Remote Exploit
Adobe ColdFusion 9 - Administrative Authentication Bypass (Metasploit)
Adobe ColdFusion 9 Administrative Login Bypass Vulnerability
Adobe ColdFusion 9 - Administrative Authentication Bypass
Adobe ColdFusion 9 - Administrative Authentication Bypass
Adobe ColdFusion 9 Administrative Login Bypass Vulnerability
Packet Storm Advisory 2013-0819-2 - Adobe ColdFusion 9 Administrative Login Bypass
Adobe ColdFusion RDS Authentication Bypass
Adobe ColdFusion APSB13-03 - Remote Multiple Vulnerabilities (Metasploit)
Adobe ColdFusion APSB13-03 Remote Exploit
Adobe ColdFusion APSB13-03 Command Execution