Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-4399

Опубликовано: 09 окт. 2012
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 5
CVSS3: 7.5

Описание

The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

РелизСтатусПримечание
devel

not-affected

1.3.15-1
hardy

not-affected

lucid

not-affected

natty

not-affected

oneiric

not-affected

precise

not-affected

upstream

not-affected

Показывать по

EPSS

Процентиль: 96%
0.12091
Средний

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 14 лет назад

The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

CVSS3: 7.5
debian
почти 14 лет назад

The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 all ...

CVSS3: 7.5
github
больше 4 лет назад

CakePHPallows remote attackers to read arbitrary files via XML data containing external entity references

EPSS

Процентиль: 96%
0.12091
Средний

5 Medium

CVSS2

7.5 High

CVSS3