CVE-2013-3350
Published Jul 10, 2013
Last updated 4 years ago
Overview
- Description
- Adobe ColdFusion 10 before Update 11 allows remote attackers to call ColdFusion Components (CFC) public methods via WebSockets.
- Source
- psirt@adobe.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:adobe:coldfusion:10.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3FAE2BA4-7CD9-4CBD-9D77-56D591FBDB24" }, { "criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C4D259E-56B1-4D53-80A9-52D0687779C4" }, { "criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "09F8F645-DD28-4159-877E-40B4C8CDA4CC" }, { "criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B83D6CF-4C45-4B7A-9AFC-9961E1FE0686" }, { "criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F54FF25A-EF5B-4DE0-802C-C9B00A963C21" }, { "criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update8:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34472770-FFCE-4088-8658-FA0A552BEAA6" } ], "operator": "OR" } ] } ]