Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows local developers to obtain the hash and gain privileges.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-4340
http://www.vupen.com/english/advisories/2005/2948
http://www.securityfocus.com/bid/15904
http://www.macromedia.com/devnet/security/security_zone/mpsb05-14.html