CVE-2013-0629

Adobe ColdFusion: Directory Traversal

As of , CVE-2013-0629 in Adobe ColdFusion is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 7 March 2022
US federal deadline
7 September 2022184 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.66Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.01 on 7 March 2022EPSS on the day CISA listed it.
Public exploit
1 Exploit-DB entry (1 verified)
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.

CISA's description

Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013.

The CVE record's description, from adobe

CVE published
9 January 2013
Assigned by
adobe
CVSS
7.5 High (CVSS 3.1, from CISA-ADP)
CWE-264
Permissions, Privileges, and Access Controls
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
partial

Timeline

  1. The CVE record was published.
  2. Exploit-DB published an exploit (EDB-ID 24946).
  3. CISA added it to its list of exploited vulnerabilities.
  4. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

ColdFusion: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-48282Path TraversalAdobe ColdFusionPatch nowForensic triage required by CISA0.42
CVE-2010-2861Directory TraversalAdobe ColdFusionPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2013-0632Authentication BypassAdobe ColdFusionPatch this weekMetasploit module; EPSS 0.94; verified Exploit-DB entry0.94
CVE-2024-20767Improper Access ControlAdobe ColdFusionPatch this weekMetasploit module; EPSS 0.990.99
CVE-2023-26360Deserialization of Untrusted DataAdobe ColdFusionPatch this weekMetasploit module; EPSS 0.970.97
CVE-2018-15961Unrestricted File UploadAdobe ColdFusionPatch this weekMetasploit module; EPSS 0.990.99
CVE-2013-0625Authentication BypassAdobe ColdFusionPatch this weekEPSS 0.94; verified Exploit-DB entry0.94
CVE-2017-3066DeserializationAdobe ColdFusionPatch this weekEPSS 0.910.91
CVE-2023-29300Deserialization of Untrusted DataAdobe ColdFusionPatch this weekRansomware use; EPSS 0.990.99
CVE-2023-38203Deserialization of Untrusted DataAdobe ColdFusionPatch this weekRansomware use; EPSS 0.970.97

All 16 entries for ColdFusion

Read further