Authentication bypass in ColdFusion - CVE-2013-0632
Published: January 13, 2017 / Updated: March 8, 2022
Vulnerability details
The vulnerability exists due to an error within administrator.cfc. A remote unauthenticated attacker can access Adobe ColdFusion application using a default empty password, login to the RDS component and leverage this session to access administrative web interface.
Successful exploitation of this vulnerability results in unauthorized access to Adobe ColdFusion.
Note: the vulnerability was being actively exploited.Affected software
How to mitigate CVE-2013-0632
Links to Public Exploits and PoC-codes
- Exploit #777 - Adobe ColdFusion 9 - Administrative Login Bypass (March 18, 2020)
- Exploit #778 - Adobe ColdFusion 9 - Administrative Login Bypass (Metasploit) (March 18, 2020)
- Exploit #779 - Adobe ColdFusion APSB13-03 - Remote Exploit (Metasploit) (March 18, 2020)
- Exploit #1503 - Adobe ColdFusion RDS Authentication Bypass (March 18, 2020)
- Exploit #1778 - Adobe ColdFusion 9 Administrative Login Bypass (March 18, 2020)