Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-4335

Опубликовано: 14 янв. 2011
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5

Описание

The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

1.3.2-1.1
hardy

ignored

end of life
karmic

ignored

end of life
lucid

ignored

end of life
maverick

ignored

end of life
natty

not-affected

1.3.2-1.1
oneiric

not-affected

1.3.2-1.1
precise

not-affected

1.3.2-1.1
quantal

not-affected

1.3.2-1.1

Показывать по

Ссылки на источники

7.5 High

CVSS2

Связанные уязвимости

nvd
почти 15 лет назад

The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.

debian
почти 15 лет назад

The _validatePost function in libs/controller/components/security.php ...

github
больше 3 лет назад

CakePHP allows remote attackers to modify internal Cake cache and execute arbitrary code

7.5 High

CVSS2