VYPR
Critical severity9.8CISA KEVNVD Advisory· Published Jan 9, 2013· Updated Apr 21, 2026

CVE-2013-0625

CVE-2013-0625

Description

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.

Affected products

3
  • cpe:2.3:a:adobe:coldfusion:9.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:adobe:coldfusion:9.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:coldfusion:9.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:coldfusion:9.0.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.