VDB

GCVE-110-CERTCC-2013-113732

GCVE-110-CERTCC-2013-113732
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published May 14, 2013
Adobe ColdFusion 9, 9.0.1, 9.0.2 with the APSB13-03 hotfix and 10 are vulnerable to a code injection vulnerability when ColdFusion is configured to not require authentication and RDS is disabled.

Risk Scores

CVSS 2.0
8.8/10
High · AV:N/AC:M/Au:N/C:C/I:C/A:N
certcc-cam
certcc-cam
impact0population0exploitation0widely_known0score_current0ease_of_exploitation0
certcc-vrda
certcc-vrda
d1_impact3d1_population3d1_direct_report1
certcc-cvss-temporal-env
certcc-cvss-temporal-env
temporal_score7.7remediation_levelOFreport_confidenceCenvironmental_score5.8target_distributionMenvironmental_vectorCDP:ND/TD:M/CR:ND/IR:ND/AR:ND

Browse GCVE Records

76,523 records in the GCVE database · Updated August 7, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›