Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-4399

Опубликовано: 09 окт. 2012
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 7.5

Описание

The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

РелизСтатусПримечание
devel

not-affected

1.3.15-1
hardy

not-affected

lucid

not-affected

natty

not-affected

oneiric

not-affected

precise

not-affected

upstream

not-affected

Показывать по

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 13 лет назад

The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

CVSS3: 7.5
debian
больше 13 лет назад

The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 all ...

CVSS3: 7.5
github
больше 3 лет назад

CakePHPallows remote attackers to read arbitrary files via XML data containing external entity references

5 Medium

CVSS2

7.5 High

CVSS3