#VU4563 Authentication bypass in ColdFusion - CVE-2013-0632
Published: January 13, 2017 / Updated: March 8, 2022
ColdFusion
Adobe
Description
The vulnerability exists due to an error within administrator.cfc. A remote unauthenticated attacker can access Adobe ColdFusion application using a default empty password, login to the RDS component and leverage this session to access administrative web interface.
Successful exploitation of this vulnerability results in unauthorized access to Adobe ColdFusion.
Note: the vulnerability was being actively exploited.