PoC Index

CVE-2013-0632

KEVHIGH 10.0EPSS 93.7%

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
93.69% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2022-03-03
Published
2013-01-17
Updated
2025-10-22

Proof-of-concept exploits (1)

Metasploit modules (1)

ExploitDB entries (3)

References

Related