Описание
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | DNE | |
| devel | not-affected | 1.3.2-1.1 |
| hardy | ignored | end of life |
| karmic | ignored | end of life |
| lucid | ignored | end of life |
| maverick | ignored | end of life |
| natty | not-affected | 1.3.2-1.1 |
| oneiric | not-affected | 1.3.2-1.1 |
| precise | not-affected | 1.3.2-1.1 |
| quantal | not-affected | 1.3.2-1.1 |
Показывать по
Ссылки на источники
7.5 High
CVSS2
Связанные уязвимости
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.
The _validatePost function in libs/controller/components/security.php ...
CakePHP allows remote attackers to modify internal Cake cache and execute arbitrary code
7.5 High
CVSS2