Executive brief
An authentication bypass vulnerability in Adobe ColdFusion's administrator.cfc allows remote attackers to gain administrative access. Attackers can log in to the RDS component using a default empty password and leverage that session to access the administrative web interface, potentially leading to arbitrary code execution.
Affected products
- Adobe ColdFusion 9.0, 9.0.1, 9.0.2, 10
Timeline
- 2013-01-16: disclosed: NVD Published Date
- 2013-01-17: other: Initial CVE Analysis
- 2013-01-01: exploited: Exploited in the wild in January 2013
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog