← Back to browse · API

CVE-2013-0632

Severity
CRITICAL
CVSS
9.8
EPSS
0.93691
Risk score
57.79
CISA KEV
Yes
PoC
No
Published
2013-01-17
Modified
2025-10-22
First seen
2026-08-07
Aliases
EUVD-2013-0643, GHSA-8XF7-V5JV-237F
Products
Adobe:ColdFusion, n/a:n/a n/a
Sources
cisa.gov CVE-2013-0632
euvd EUVD-2013-0643

Description

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.

References