'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2013-0625: Adobe ColdFusion scheduleedit.cfm Authentication Bypass Vulnerability
Severity:mid
CVE ID:CVE-2013-0625
| Descripiton:
|
An authentication bypass vulnerability affects ColdFusion servers. The bypass allows an unauthenticated attacker to create a scheduled task which will be performed and allow attacker-controlled code to be uploaded to the vulnerable server. This vulnerability could be exploited though Remote Development Services (RDS) or Administrator interfaces if they do not require authentication or through CSRF if APSB12-26 has not been applied. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.