VDB
GCVE-110-CERTCC-2013-113732
GCVE-110-CERTCC-2013-113732
Advisory PublishedCVSS 8.8/10
Adobe ColdFusion 9, 9.0.1, 9.0.2 with the APSB13-03 hotfix and 10 are vulnerable to a code injection vulnerability when ColdFusion is configured to not require authentication and RDS is disabled.
Risk Scores
CVSS 2.0
8.8/10
High · AV:N/AC:M/Au:N/C:C/I:C/A:N
certcc-cam
certcc-cam
impact0population0exploitation0widely_known0score_current0ease_of_exploitation0
certcc-vrda
certcc-vrda
d1_impact3d1_population3d1_direct_report1
certcc-cvss-temporal-env
certcc-cvss-temporal-env
temporal_score7.7remediation_levelOFreport_confidenceCenvironmental_score5.8target_distributionMenvironmental_vectorCDP:ND/TD:M/CR:ND/IR:ND/AR:ND
Aliases
References
Browse GCVE Records
76,523 records in the GCVE database · Updated August 7, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.