Input validation error in ColdFusion - CVE-2013-3350

 

Input validation error in ColdFusion - CVE-2013-3350

Published: July 10, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU42727
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-3350
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Adobe ColdFusion 10 before Update 11 allows remote attackers to call ColdFusion Components (CFC) public methods via WebSockets.


Affected software

ColdFusion

How to mitigate CVE-2013-3350

Install update from vendor's website.


External References

Related Security Bulletins