Adobe has released a security hotfix for ColdFusion 10, 9.0.2, 9.0.1 and 9.0 for Windows, Macintosh and UNIX. This hotfix addresses vulnerabilities that could permit an unauthorized user to remotely circumvent authentication controls, potentially allowing the attacker to take control of the affected server.
Adobe is aware of reports that four vulnerabilities (CVE-2013-0625, CVE-2013-0629, CVE-2013-0631 and CVE-2013-0632, referenced in Security Advisory APSA13-01) are being exploited in the wild against ColdFusion customers. Adobe recommends users update their product installation.
- Apply the ColdFusion Security hotfix APSB13-03 listed in the Web references section.
CVE-2013-0625 CVE-2013-0629 CVE-2013-0631 CVE-2013-0632
- WordPress Plugin Social Media and Share Icons (Ultimate Social Media) Security Bypass (1.5.1)
- WordPress Plugin Contact Form 7 Multi-Step Forms Security Bypass (3.0.8)
- Joomla! Core 1.5.x Security Bypass (1.5.0 - 1.5.14)
- Joomla! Core 1.6.x Security Bypass (1.6.0 - 1.6.6)
- WordPress Plugin IgnitionDeck Security Bypass (1.1.6)