CVE-2013-0632
KEVHIGH 10.0EPSS 93.7%
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 93.69% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-03-03
- Published
- 2013-01-17
- Updated
- 2025-10-22
Proof-of-concept exploits (1)
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/30210
- https://www.exploit-db.com/exploits/24946
- https://www.exploit-db.com/exploits/27755