CVE-2013-5326
- EPSS 0.49%
- Veröffentlicht 13.11.2013 01:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 12, 9.0.1 before Update 11, 9.0.2 before Update 6, and 10 before Update 12, when the CFIDE directory is available, allows remote authenticated users to inject arbitrary we...
CVE-2013-5328
- EPSS 0.96%
- Veröffentlicht 13.11.2013 01:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Adobe ColdFusion 10 before Update 12 allows remote attackers to read arbitrary files via unspecified vectors.
- EPSS 1.62%
- Veröffentlicht 20.09.2013 16:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read ...
- EPSS 0.69%
- Veröffentlicht 10.07.2013 10:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in Adobe ColdFusion 9.0 through 9.0.2, when the JRun application server is used, allows remote attackers to cause a denial of service via unknown vectors.
- EPSS 1.61%
- Veröffentlicht 10.07.2013 10:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Adobe ColdFusion 10 before Update 11 allows remote attackers to call ColdFusion Components (CFC) public methods via WebSockets.
- EPSS 21.56%
- Veröffentlicht 16.05.2013 11:45:30
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 11, 9.0.1 before Update 10, 9.0.2 before Update 5, and 10 before Update 10 allows remote attackers to execute arbitrary code via unknown vectors.
- EPSS 85.89%
- Veröffentlicht 09.05.2013 12:31:19
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to read arbitrary files via unknown vectors.
CVE-2013-1387
- EPSS 1.85%
- Veröffentlicht 10.04.2013 03:48:20
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 10, 9.0.1 before Update 9, 9.0.2 before Update 4, and 10 before Update 9 allows attackers to impersonate users via unknown vectors.
CVE-2013-1388
- EPSS 1.85%
- Veröffentlicht 10.04.2013 03:48:20
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 10, 9.0.1 before Update 9, 9.0.2 before Update 4, and 10 before Update 9 allows attackers to obtain administrator-console access via unknown vectors.
- EPSS 92.37%
- Veröffentlicht 17.01.2013 00:55:01
- Zuletzt bearbeitet 22.10.2025 01:15:47
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to ac...