PT-2013-2479 · Adobe · Coldfusion

Published

2013-01-09

·

Updated

2025-02-13

·

CVE-2013-0625

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Adobe ColdFusion versions 9.0 through 9.0.2
Description The issue allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors when a password is not configured. This has been exploited in the wild in January 2013.
Recommendations For Adobe ColdFusion versions 9.0 through 9.0.2, configure a password to prevent authentication bypass.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0625

Affected Products

Coldfusion