CVE-2013-0632
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe ColdFusion Authentication Bypass Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 94% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-276
מוצרים מושפעים
adobe: coldfusion
קישורים
- http://www.adobe.com/support/security/advisories/apsa13-01.html MitigationVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb13-03.html Broken LinkVendor Advisory
- http://www.adobe.com/support/security/advisories/apsa13-01.html MitigationVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb13-03.html Broken LinkVendor Advisory
- http://www.exploit-db.com/exploits/30210 ExploitThird Party AdvisoryVDB Entry
- http://www.exploit-db.com/exploits/30210 ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource