Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-01-08 17:55
Updated : 2013-01-17 20:50
NVD link : CVE-2013-0625
Mitre link : CVE-2013-0625
JSON object : View
CWE
CWE-255
Credentials Management Errors
Products Affected
adobe
- coldfusion