7.5
CVSSv3

CVE-2012-4399

Published: 09/10/2012 Updated: 15/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Xml class in CakePHP 2.1.x prior to 2.1.5 and 2.2.x prior to 2.2.1 allows remote malicious users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

Vulnerable Product Search on Vulmon Subscribe to Product

cakefoundation cakephp

Exploits

# Exploit title: CakePHP XXE injection # Date: 01072012 # Software Link: wwwcakephporg # Vulnerable version: 2x - 220-RC2 # Tested on: Windows and Linux # Author: Pawel Wylecial # h0wlpl 1 Background Short description from the project website: "CakePHP makes building web applications simpler, faster and require less code" ...